Context-Inappropriate Capability
Medium
- Confidence
- 80% confidence
- Finding
- The skill is presented as orchestration/design documentation, but its example code performs real outbound API calls using an environment-sourced API key and sends task content, context, and tool definitions to a third party. In a skill context, this creates a data exfiltration and unintended network-access risk if users copy or run the sample without understanding its security implications.
