Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill declares the `exec` capability even though its documented purpose is a hosted, read-only API gateway. Granting shell execution unnecessarily expands the attack surface: a compromised or prompt-injected workflow could execute local commands, access environment variables such as API keys, or perform unintended network activity beyond the stated read-only scope.
