Context-Inappropriate Capability
Medium
- Confidence
- 83% confidence
- Finding
- The test recursively scans local files for secret-like patterns, which extends the skill’s access and inspection scope beyond its declared JSON/OpenAPI function. In an agent-skill context, unnecessary filesystem scanning can expose sensitive content in nearby files, logs, or test output and normalizes overbroad data access.
