Scope Creep
High
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs subagent execution with `security: "full"` and references `curl`/exec-based operations, while the manifest only declares `disk_write`. That creates a permission mismatch and can cause the skill to run with broader capabilities than users or policy expect, increasing the blast radius if the workflow or any fetched content is abused.
