Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly depends on an external code CLI and LLM API connectivity, which expands the trust boundary beyond local PTY execution and file sync into remote processing of prompts, code, and possibly project data. In a code-execution skill, this can expose sensitive source files or credentials to external services if users assume the tool is purely local.
