Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill accepts an arbitrary `callback_url` for a primarily local PDF-processing workflow, which unnecessarily expands the trust boundary to outbound network destinations. In an agent context, this can enable unintended data exfiltration, SSRF-like requests, or sending document-derived results to attacker-controlled endpoints without a tightly scoped business need.
