Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- This utility includes an execution path that permanently deletes files from the skill's example library via `filepath.unlink()` when invoked with `prune --execute`. While the code appears intended for maintenance rather than abuse, destructive file-deletion capability is not necessary for a blog-writing skill's core function and creates avoidable risk if the script is run accidentally, pointed at unexpected content, or exposed through an agent workflow.
