Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The script recursively scans JSONL session transcript files from a hard-coded agents directory and uses their contents to infer skill usage, even though those transcripts may contain unrelated or sensitive agent interaction data. This creates an unnecessary data access surface and can expose private operational history without explicit user consent, especially because the path is outside the provided workspace root.
