Context-Inappropriate Capability
Medium
- Confidence
- 86% confidence
- Finding
- The documentation exposes a destructive `dmon delete` capability for removing monitoring points, while the skill description emphasizes device management, monitoring, read/write point data, alarms, history, grouping, and bulk operations—not deletion of monitoring definitions. In an industrial IoT context, deleting monitoring points can impair observability, break automation workflows, and hinder alarming or operator awareness, making this more dangerous than a typical admin convenience command.
