Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The guide includes direct shell and repository path access instructions using `sudo -u git` and filesystem paths, which expands the skill from GitLab work-statistics reporting into host-level repository access. Even if framed as read-only, this increases attack surface, bypasses intended application/API boundaries, and could enable broader data access than needed for the stated purpose.
