Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly encourages shell execution via `npx` and offers local credential persistence under `~/.config/sentisense/`. Even though the package/version is pinned and the skill is read-only in business purpose, invoking external code and storing secrets on disk expands the attack surface beyond simple API use and can expose hosts that allow shell access.
