Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly prints up to 5,000 characters from each of the first 30 code files in the target project, which can expose proprietary source code, embedded secrets, credentials, or sensitive business logic to the model/session output. For a documentation tool, broad raw code disclosure is not necessary because the skill can analyze files locally and emit synthesized documentation instead.
