Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to invoke a local Node script to push a generated file directly to a recipient, which extends beyond normal content generation into external file delivery. This creates a capability boundary violation: if the receiver or file path is influenced by context or future changes, the skill could exfiltrate data or send unsolicited files without an explicit user approval step.
