Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly encourages `source workflows/components/connections/api-auth.sh`, which executes arbitrary shell code from a reusable component path rather than treating connection data as inert configuration. In an agent skill with `exec` capability, this broadens the trust boundary and can enable hidden command execution, credential exfiltration, or environment tampering if a connection script is modified or replaced.
