Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a JSON formatting/validation utility, but later advertises command execution capability unrelated to that purpose. Unnecessary exec capability expands the attack surface and can cause an agent to run shell commands based on untrusted JSON content or ambiguous user prompts, creating avoidable system-risk for a task that should be purely local parsing/formatting.
