Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The `list_all` functionality enumerates all persisted agent state, including agent identifiers, model history metadata, channels, and pending notification status, which goes beyond the skill’s stated purpose of notifying the current session user about model switches. In an agent-skill context, bulk enumeration increases cross-session visibility and can leak operational metadata about other agents or users if the command is reachable by unintended callers.
