Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill declares the `exec` tool even though its stated purpose is only to write API documentation. Unnecessary shell execution expands the attack surface: a prompt-injected user request or future skill logic could trigger command execution, potentially exposing local files, environment variables, or credentials such as the documented API key.
