Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs creation of a local order file specifically for another skill (`clawtip`) to consume, creating cross-skill state coupling through the filesystem. This is dangerous because it enables confused-deputy behavior, weakens isolation between skills, and can allow one skill to influence another skill's privileged payment flow using locally staged data.
