Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill declares `exec` capability even though its documented purpose is health-data querying and analysis, which does not inherently require arbitrary shell access. In an agent environment, this materially expands the attack surface: prompts or downstream workflow logic could invoke system commands, enabling data exfiltration, local file access, or command abuse unrelated to the stated skill purpose.
