Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script logs both raw process arguments and the parsed argument object, which can expose sensitive notification contents such as titles, bodies, identifiers, or operational context to stdout, logs, and calling systems. In an agent/automation environment, stdout is often centrally collected or visible to other components, making this a real confidentiality issue unrelated to the skill's core purpose.
