Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The README includes a webhook receiver that invokes local commands via subprocess in response to remote HTTP requests. Even though the commands are hardcoded, this still introduces a remotely triggerable execution path and unsafe operational pattern that expands the attack surface beyond simple report generation, especially if the endpoint is exposed or the token check is weak or omitted in real deployments.
