Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as an HTML coding tool, but it also advertises generic external API integration capability without tightly scoping that capability to HTML-specific workflows. This broadens the trust boundary and can enable unintended data exfiltration or interaction with arbitrary remote services if an agent invokes the skill based on its broad claims.
