Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly authorizes `exec + curl` to scrape public pages, which expands a rental-advice skill into arbitrary command execution territory. Even if intended for web retrieval, shell-capable tooling materially increases the risk of command injection, unsafe external access, and misuse beyond the stated business purpose, especially when downstream inputs may be influenced by users or untrusted content.
