Context-Inappropriate Capability
Low
- Confidence
- 95% confidence
- Finding
- The file includes local absolute filesystem paths in `source_skills`, which can disclose the developer's username, workstation directory layout, and local environment details. While this does not itself enable code execution, it creates unnecessary information disclosure that can aid targeted social engineering, environment fingerprinting, or path-based follow-on attacks if the artifact is shared outside the originating machine.
