Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script disables SSH host key verification with StrictHostKeyChecking=no, which allows connections to proceed without validating the remote server's identity. In a tool specifically intended for remote command execution on Windows hosts, this creates a realistic man-in-the-middle risk where an attacker could impersonate the target host, capture commands, or induce execution against an attacker-controlled system.
