Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill is framed as a read-only repository audit, but it explicitly instructs the agent to run external CLI commands (`brigade handoff doctor` and `brigade memory care scan`). Even if intended for diagnostics, external tools can perform network access, write files, load plugins, or execute repository-defined behavior, turning a passive audit into active code/tool execution on adversarial input.
