Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The manifest enables system command execution even though the stated purpose is secure credential storage and encryption. That capability materially expands the attack surface: a compromised or overly permissive skill could invoke shell commands to read, copy, or exfiltrate credentials from memory or workspace files, which is especially risky in a credential-management context.
