Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a SQL generator, but the documentation also exposes broad command-execution capability that is not tightly scoped to SQL generation. In an agent environment with read/exec/write tools, this expands the attack surface and can enable arbitrary system actions if the skill is activated by loosely related prompts or abused through prompt injection.
