Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- This skill is for generating presentations, but the local settings grant Bash execution for rsync, which is not necessary for rendering markdown, fetching design docs, or exporting HTML/PDF. Allowing shell-backed file synchronization expands the attack surface and could enable unintended file copying, data exfiltration, or movement of local content if the skill or its inputs are abused.
