Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The optional plan workflow probes multiple local credential locations and environment indicators even though the skill's primary purpose is code generation. Enumerating credential-source presence reveals sensitive environmental information and expands the skill into local security-context inspection, which may be unnecessary and privacy-invasive.
