Context-Inappropriate Capability
Medium
- Confidence
- 85% confidence
- Finding
- The skill instructs setting environment variables as part of execution even though a reporting/evaluation skill should not need to mutate execution environment by default. This can leak sensitive paths or credentials into downstream tooling, expand the attack surface for chained commands, and normalize hidden state changes that users did not request.
