Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill goes beyond image generation and instructs the agent to help download remote image outputs to a user-specified local path. That expands capability from API mediation into local file write behavior, which can be abused for unintended filesystem changes or writing untrusted content without clear user safety checks.
