Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The documented optional `appid` parameter enables WeChat mini-program notification delivery, which expands the skill from image analysis into outbound messaging. In a medical context involving children’s bone-age assessments, this creates unnecessary data-flow expansion and increases privacy/compliance risk if patient-linked results or identifiers are pushed to third-party messaging ecosystems without clear user consent and strict purpose limitation.
