Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill exposes hardcoded root SSH credentials in plaintext and presents them as the default environment for use. Anyone with access to the skill can attempt privileged access to the referenced server, enabling full system compromise, data theft, service disruption, and lateral movement.
