Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill is a pure Markdown advisory guide, but its manifest exposes the `exec` tool without any functional need shown in the content. Unnecessary execution capability expands the attack surface: an agent could be induced to run shell commands during workflow setup or troubleshooting, turning a read-only instructional skill into one capable of system-side effects.
