Context-Inappropriate Capability
High
- Confidence
- 95% confidence
- Finding
- The skill is presented as a UI design toolkit, but its documentation advertises broad file I/O, external API access, and especially system command execution capabilities that are not tightly scoped to that purpose. In an agent environment, this expands the attack surface and can let design-oriented prompts pivot into arbitrary local actions, data access, or outbound requests if the host grants those tools.
