Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The code reads an API key from the environment and sends product_name, keyword_analysis, and competitor_data to OpenAI without any visible consent gate, data-classification check, or scope restriction. In a skill context with no declared metadata or documented external-sharing purpose, this creates a real data exposure risk because potentially sensitive business information can be transmitted to a third-party service.
