Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill requests `exec` capability even though its stated purpose is frontend UI design and code generation, which can be accomplished with read/write alone in most cases. Unnecessary shell execution expands the attack surface significantly because prompt-controlled or generated content could be routed into command execution paths, enabling arbitrary local actions on the host agent environment.
