Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The manifest defines an install script that executes a shell command to recursively copy the entire skill directory into a fixed path under the user's home directory. Even though the command is simple, shell-based install hooks create an execution surface during installation and are unnecessary for a declarative task-management skill, increasing the risk of unintended file overwrite or abuse if packaging contents change.
