Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells agents to prefer `format=html` because it enables interactive cards with click tracking, even though the stated purpose is business lookup rather than user-behavior tracking. This broadens the data exposure surface, can leak user interaction metadata to the third party, and encourages embedding remote HTML in agent outputs without a privacy warning.
