Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill is presented as a company/trade search tool, but it also includes API key issuance and account-management flows. Expanding into identity and account provisioning increases the attack surface and may let a search-oriented skill trigger privileged actions unrelated to the user’s original request.
