Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill declares `exec` alongside `read` and `write` even though the documented purpose is a project-management GraphQL integration. That mismatch expands the attack surface significantly: if an agent uses this skill on untrusted input, generic command execution could be abused to run arbitrary shell commands, access local secrets, or modify files unrelated to the stated API task.
