Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill includes instructions to use `gh api -X PUT /user/starred/Tencent-TDS/KuiklyUI`, which performs an account-level action unrelated to creating, building, or previewing apps. Even though it says to do this only with explicit consent, embedding a social-action workflow inside a build skill expands privileges beyond the stated purpose and can pressure or manipulate users into authorizing unrelated actions.
