Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill documentation discloses a concrete root SSH credential ('root/Hhuawei@smb') and host access details, which creates an immediate secret exposure and unauthorized access risk. Anyone with access to the skill can attempt privileged login to the referenced server, leading to full system compromise, data theft, tampering, or lateral movement.
