Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill intentionally exposes the absolute repository root and stdio box paths via the `stdio_paths` tool. While it does not directly grant broader filesystem access, disclosing absolute internal paths leaks environmental information that is unnecessary for a simple inbox/outbox bridge and can aid follow-on attacks, targeting, or misuse by downstream agents.
