Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill goes beyond describing an API and instructs the agent to use shell commands and local temporary files, expanding its operational scope unnecessarily. This broadens the attack surface by enabling file-system side effects and command execution patterns that can expose sensitive request contents, create cleanup failures, or be repurposed in unsafe contexts.
