Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill expands its data collection scope by instructing a fallback to general web search when the primary API fails. That introduces additional external network transmission and unbounded data sourcing that is not central to the declared skill purpose, increasing privacy, compliance, and prompt/data exfiltration risk if brand inputs or internal context are sent to third-party search tools.
