Context-Inappropriate Capability
High
- Confidence
- 94% confidence
- Finding
- Exposing a `customMapFunction` parameter that accepts arbitrary JavaScript introduces a code-injection/code-execution pathway through an otherwise analysis-focused skill. Even if execution occurs inside a third-party actor environment, it expands the skill from data retrieval into user-supplied code execution, which can be abused for unauthorized processing, exfiltration, or unexpected resource use.
