Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The manifest requests the `exec` tool, which grants shell execution, even though the described skill is only a journaling virtual pet. This creates an unnecessary high-risk capability that could be abused to run arbitrary system commands, access local files, or pivot beyond the skill’s stated purpose. The mismatch between benign product description and powerful execution rights makes the context more suspicious, not less.
