Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The handler invokes an external CLI via execSync to obtain usage data, which expands the trust boundary from local code to the shell environment and whatever executable resolves as clawdbot. In an agent-skill context, this is risky because PATH hijacking, unexpected shell execution semantics, or a compromised external tool could cause arbitrary code execution or unintended side effects under the skill's privileges.
