Context-Inappropriate Capability
Low
- Confidence
- 86% confidence
- Finding
- The skill includes explicit shell-style commands to read memory-bank files and list image directories, which grants the agent operational file-system discovery behavior beyond what is necessary for a visual storytelling role. Even though the commands appear aimed at gathering brand context, they normalize local file access and pattern-based searching, which could expose sensitive project data if the agent runs with broader workspace permissions.
