Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The tool trusts a server-provided download_url and fetches it with no host allowlist, scheme restriction beyond http/https, size limits, or redirect validation. A compromised or malicious API response could coerce the local agent into making arbitrary outbound requests and writing attacker-controlled content to disk, creating an SSRF-style primitive and untrusted file write behavior.
