Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill declares `exec` capability even though the document describes a largely markdown/LLM-driven social media optimization workflow and does not define concrete commands, inputs, or execution boundaries. This creates an unnecessary arbitrary command-execution surface: an agent may invoke shell commands based on user-controlled content or vague workflow steps, which can lead to file access, network pivoting, or environment secret exposure.
