Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill requests Bash even though the documented functionality is a local front-end caregiving dashboard using localStorage. Unnecessary shell access expands the attack surface significantly: if the agent is induced to use Bash, sensitive patient data could be read, copied, exfiltrated, or system files modified despite no legitimate need for command execution.
