Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The documented workflow expands from SQL-based read-only reporting into direct shell execution of Git against on-disk repositories over SSH. Even though it is framed as read-only and warns against sudo, it still instructs an agent to access repository filesystem paths and interpolate user-controlled values such as username and dates into a shell command, broadening the capability surface beyond the skill’s stated purpose and increasing the risk of unauthorized repository metadata access or command injection in downstream implementations.
