Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill’s core purpose is to generate markdown notes from a YouTube video, but it explicitly instructs the agent to offer saving the output into external services or local files. That expands the skill’s operational scope into data exfiltration, persistence, and side-effectful actions that may trigger additional tool use without the user initially requesting those integrations, increasing the chance of oversharing or unsafe writes.
