Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill requests `exec` permission even though its documented behavior is limited to presenting static brand and feature information. Granting command-execution capability unnecessarily expands the attack surface: if the referenced script or surrounding environment is modified, the skill could run arbitrary shell commands under the agent's privileges.
