Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill is a template-based writing assistant, but its manifest requests `exec` alongside `read` and `write` without any documented need to run commands. Over-privileging an agent skill increases the attack surface: if the skill is ever extended, misused, or invoked by a broader agent workflow, command execution could enable unintended system access or abuse unrelated to its stated purpose.
