Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a documentation-writing assistant, but it declares `exec` capability without a clear functional need or strong safety boundaries. That mismatch expands the attack surface: a user or downstream prompt injection could cause command execution in a context where users reasonably expect only text generation.
