Context-Inappropriate Capability
Medium
- Confidence
- 79% confidence
- Finding
- The skill advertises an `exec` tool alongside broad remote IDE and node invocation workflows, which expands capability beyond narrowly scoped file/language/Git actions into general command execution. In an agent setting, this can enable arbitrary local or remote commands, increasing the risk of filesystem damage, credential exposure, or host compromise if the agent is prompted unsafely.
