Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill's stated purpose is syncing reports into a local knowledge base, but it also adds a capability to generate anonymous share links for reports. That expands the data exposure surface beyond ingestion and could allow report contents to be accessed by anyone possessing the tokenized URL, especially if users are not explicitly warned or did not request sharing.
