Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill declares `exec` capability even though its stated purpose is code-quality guidance, formatting, and review. Command execution materially expands the attack surface because a prompt or downstream workflow could cause the agent to run arbitrary local commands, access sensitive files, or alter the environment without that risk being clearly justified in the manifest.
