Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The document instructs the agent to register and verify third-party TranscriptAPI accounts on the user's behalf, including handling email-based OTP verification and retrieving an API key. That capability is unrelated to a YouTube channel browsing skill and materially expands the skill into credential acquisition and external account management, which increases the risk of secret handling abuse and unauthorized actions.
