Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The manifest requests `exec` permission even though the documented behavior is only to return copyright and brand information via a simple script. Granting shell execution unnecessarily expands the attack surface: if the script or surrounding skill files are modified, the agent would be authorized to execute commands on the host despite the skill's low-privilege purpose.
