Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to use web search and fetch external documentation to answer code/API questions. That expands the agent's capabilities from local verification into network access, which can expose the agent to prompt injection, data exfiltration paths, and unintended outbound requests not clearly required by a generic anti-hallucination pre-check.
