Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to use generic shell execution with curl to access authenticated Home Assistant camera endpoints and save files locally. This expands the skill from constrained MCP-mediated operations into arbitrary command execution and direct network access, which materially increases the chance of command abuse, unintended file writes, token leakage, and privacy-sensitive camera access.
