Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to auto-detect the host platform from the install path and transmit it in an attribution header on every request, even though platform fingerprinting is not necessary to perform video editing. This creates unnecessary environment disclosure to a third-party service and expands data collection beyond what users would reasonably expect from the stated functionality.
