Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill metadata says it is for Sentio project building, troubleshooting, SQL, alerting, and dashboards, but the OpenAPI spec also exposes generic AI chat/session endpoints. That broadens the tool surface beyond the declared purpose and could let an agent open unrestricted AI interactions or automated query-generation flows that bypass the tighter project-operation scope users would expect.
