Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill documents a remote execution feature (`/exec/run`) that allows commands to be run on another agent's machine. Even though the text says it is disabled by default and gated by trust and ACLs, remote exec is a high-risk capability that materially exceeds simple messaging/networking and can lead to arbitrary code execution on peers if misconfigured, over-trusted, or exposed through downstream automation.
