Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill requests the `exec` tool, which enables arbitrary shell command execution, yet the stated functionality is journaling and virtual-pet interaction with no clear operational need for shell access. This creates unnecessary attack surface: if the skill logic or prompts are influenced by untrusted input, the agent could be induced to run system commands, access local data, or chain into broader compromise.
