Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to execute a shell command to automatically open a generated HTML file in the browser. Launching a local application is a side effect beyond core data transformation, and doing so without explicit user confirmation increases the risk of unexpected command execution or browser launch from untrusted workflow content.
