Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to pull work data from Cotrace when the user asks to record work but does not provide details, expanding the data sources beyond the declared auwomo task CLI workflow. This can cause unintended cross-skill data access, privacy leakage, or inaccurate task records because the user did not explicitly consent to using another system as the source of truth.
