Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The documented command set includes provider management operations such as `providers {list,add,import,overwrite <id>}`, which expands the skill from passive audit/inventory into potentially state-changing credential administration. In a security-focused skill, exposing these capabilities without strong scope limits or confirmation requirements can lead an agent to touch sensitive provider credentials or alter configuration beyond what the user expected.
