Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The README exposes system-administration actions that go beyond ordinary opencode automation, including killing processes, changing file ownership and permissions, and altering firewall settings. In an agent skill context, documenting these commands without strict scoping or approval guidance increases the chance an agent or user will perform impactful host-level changes unrelated to the requested task.
