Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs use of `yt-dlp --dump-json` for video search, which introduces general shell execution for a non-essential feature. Even if the example command is fixed, normalizing shell-based retrieval for user-derived queries increases the risk of command injection, unsafe process spawning, and unnecessary expansion of the agent's attack surface.
