Context-Inappropriate Capability
Medium
- Confidence
- 85% confidence
- Finding
- The workflow explicitly instructs the agent to execute a shell command returned by `upload_videos`. That expands the skill from API-driven video editing into arbitrary command execution based on remote output, which creates command-injection and unintended local-action risk if the command is malformed, compromised, or substituted.
