Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly classifies itself as requiring EXEC capability even though its documented tasks are primarily document review, diffing, summarization, and citation checking. Unnecessary command execution expands the attack surface by enabling shell invocation in a context handling sensitive legal documents, making prompt-injection or unsafe future extensions more dangerous.
