Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill invokes shell commands via execSync and directly runs another skill's lifecycle script using a shell-built command containing a filesystem path. Although the current path is derived from HOME and appears non-user-facing, this expands the skill's capability from passive health observation into command execution and cross-skill control/status inspection, increasing attack surface and creating command/path injection and trust-boundary risks if environment variables or workspace contents are manipulated.
