Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill advertises API/network usage despite being presented as a frontend design tool, creating capability creep that is not clearly tied to its stated purpose. This can mislead users into granting broader permissions or exposing credentials for functions they do not expect, increasing the attack surface for data exfiltration or unauthorized remote access.
