Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly advertises general command execution capability and also declares the 'exec' tool in metadata, which creates a real risk of the agent being induced to run shell commands outside the narrow email-management purpose. In an agent setting, broad exec access materially increases the blast radius of prompt injection, unsafe automation, and unintended local/system actions.
