Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The download command accepts any user-supplied URL and writes the response to any user-supplied output path without restricting the host, scheme, or file destination. In an agent skill context, this expands the tool from a Pexels helper into a generic fetch-and-write primitive, which can enable unintended external access, retrieval of untrusted content, or overwriting local files if upstream prompts or inputs are influenced by an attacker.
