Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill declares `exec` even though the documented function is code formatting/review/fixing, which can usually be performed on provided text without shell execution. This unnecessarily expands the attack surface: a user or prompt-injected code sample could steer the agent into running local commands, causing command execution or data exposure in contexts where execution was never needed.
