Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The document is primarily a policy/guidance skill, but it embeds executable integration code that reads a secret from the environment and performs an outbound API call to a third-party service. In an agent-skill context, this can normalize or induce secret use and data exfiltration behavior beyond the user-facing notification guidance, especially without any trust, consent, or data-handling constraints.
