Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The declared purpose of this skill is Pillow-based image processing, but the dependency list also includes openpyxl, a spreadsheet library unrelated to that stated scope. Unnecessary capabilities expand the attack surface, increase supply-chain risk, and may enable unexpected file parsing behaviors that are not needed for the advertised functionality.
