Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The skill documentation states it will auto-commit and push content to GitHub, which is a side effect beyond simple content generation and is not reflected in the declared permissions. This creates a trust and capability mismatch that can lead to unauthorized repository modification or hidden publication behavior if users rely on the manifest to understand risk.
