Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The manifest requests the "exec" permission, which enables shell command execution and materially expands the attack surface of the skill. In a pharmacy-management context handling sensitive operational and potentially regulated data, shell execution is not clearly justified by the manifest alone, so a compromised or poorly designed skill could run arbitrary commands, access local files, or invoke other system tools.
