Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill reads host-level systemd journal logs via `journalctl`, which exposes potentially sensitive operational data such as internal errors, service state, paths, tokens accidentally logged, or other users' activity. Given the stated code purpose is reporting session costs and recent errors, broad host log access is more privileged than necessary and increases the blast radius if the skill is misused or compromised.
