Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The runbook explicitly instructs the agent to log the user's raw input along with detailed step-by-step execution traces, including commands, status, latency, and output metadata. For a trip-planning skill, this creates unnecessary collection of potentially sensitive travel details and operational telemetry without any stated minimization, retention limit, or user disclosure, increasing privacy and misuse risk.
