Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill directs the agent to invoke `exec` with shell-specific commands, which expands the attack surface from a simple password-generation task to arbitrary command execution. Even though the provided commands are fixed examples for calling an API, encouraging shell execution for user-influenced parameters can create command-injection and unsafe tool-use risks in agent environments.
