Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent/user to type email credentials into a browser automation flow. Even though manual login is relevant to accessing mail, embedding credential-entry steps in an agent skill creates a direct path for credential exposure through logs, screenshots, terminal history, model context, or tool telemetry. In the context of an email-summary skill, this is more dangerous because mailbox access can expose large amounts of sensitive personal and business data.
