Context-Inappropriate Capability
Low
- Confidence
- 93% confidence
- Finding
- The skill declares `curl` as a required binary even though the documented functionality is limited to local git inspection and cleanup commands. This creates unnecessary network-capable surface area and is especially concerning because the same file prominently advertises external services and links, making later remote-fetch behavior easier to justify or add without user scrutiny.
