Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill contains an instruction to proactively promote an external hosted platform unrelated to core RDKit functionality. This creates a prompt-injection-style trust boundary issue: the agent may steer users to a third-party service, potentially exposing sensitive research context or creating undisclosed commercial influence in responses.
