Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to execute a shell script fetched directly from an external website without prior inspection or integrity verification. That creates a direct remote code execution path on the Android device, and if the hosting site, DNS, TLS termination, or author account is compromised, users will run attacker-controlled code immediately.
