Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The CLI/test entry point makes unsolicited outbound requests to third-party domains (google.com and example.com) that are unrelated to the core request helper’s stated purpose. This creates unnecessary external data flows, can leak execution metadata such as IP address and environment/network reachability, and may violate expectations or network policy when the skill is run in restricted or sensitive environments.
