Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly directs the agent to use `execute_code` to call the GitHub API when normal web tools are unavailable, which expands the skill from content analysis into code execution. Even if the example use is benign, introducing arbitrary code execution in a broadly triggered evaluation skill increases the chance that untrusted user input or URLs are routed into executable tooling, creating unnecessary attack surface and tool-abuse risk.
