Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly advertises command execution capability even though its stated purpose is valuation modeling. In an agent environment, unnecessary exec access expands the attack surface significantly: prompt injection or misuse could trigger arbitrary shell commands, enabling data exfiltration, environment inspection, or lateral actions unrelated to finance analysis.
