Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill is described as a Markdown/LLM guidance tool, yet it declares exec capability alongside read/write. That unnecessarily expands the attack surface: a prompt-injected or mis-triggered workflow could execute shell commands on the host despite the skill's documented purpose not requiring code execution.
