Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The function is a generic wrapper over the EMR OpenAPI and forwards a caller-controlled `action` directly to the backend without any local allowlist or role restriction. In a skill context, this broadens the callable surface from a narrowly scoped 'agent manager' into an arbitrary EMR operation proxy, which can enable unauthorized state changes, information disclosure, or destructive actions if higher layers fail to constrain inputs.
