Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill advertises private local tracking, but the default settings and data model explicitly support outbound delivery modes, channels, recipients, and webhooks. In a menstrual-health tracker, enabling external routing of reminders materially increases privacy risk because sensitive reproductive-health inferences can be sent to third parties or misconfigured destinations.
