Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a kanban-board management capability, but the documentation exposes materially broader administrative actions including project sharing, user lookup, password-change flows, token lifecycle management, and database-level permission changes. That expansion of scope increases the chance an agent or operator will use the skill for identity, authorization, or persistence-affecting actions that were not intended or sufficiently controlled.
