Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The prompt instructs the agent to execute Windows PowerShell commands as a fallback for counting lines in a generated file. Even though the command is simple, it expands the skill's operational scope from document analysis into shell execution, which increases attack surface and can normalize command execution in a workflow that does not inherently require it. The surrounding skill context is document decomposition, so this capability is less justified and therefore more concerning.
