Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The cron 'dry-run' guidance explicitly allows running the cron payload in an isolated subagent or exec dry-run context, which can still result in real command execution. For a testing/evaluation skill, that blurs the safety boundary and could execute side-effecting payloads under the guise of validation, especially if the cron job invokes scripts or external commands.
