Context-Inappropriate Capability
Medium
- Confidence
- 85% confidence
- Finding
- The custom logging example sends structured log entries to an external endpoint and the surrounding examples encourage inclusion of request URLs, methods, user IDs, stack traces, and arbitrary metadata. In an observability context this is plausible and not inherently malicious, but the example lacks minimization, redaction, and privacy guidance, so it normalizes exporting potentially sensitive operational or user data to third parties.
