Scope Creep
Medium
- Confidence
- 94% confidence
- Finding
- The skill declares the "exec" tool even though its stated purpose is only to fetch hosted news and flash data. Granting command execution expands the attack surface significantly because any future skill logic or prompt-influenced behavior could invoke shell commands, making a read-only data skill capable of arbitrary local actions.
