Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill instructs the agent to automatically install or upgrade a tool by fetching and executing a remote shell script from GitHub via curl | bash. That creates a direct remote code execution path unrelated to merely processing XLSX files, and it also introduces supply-chain risk if the repository, network path, or referenced script is compromised.
