Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill requests generic exec access even though its core functions are simple local password generation and strength evaluation that could be implemented without shell execution. Broad execution capability expands the attack surface: if an agent invokes this skill or follows future prompt paths through exec, it could run unintended local commands or process sensitive local data beyond the stated scope.
