Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The embedded Python performs an outbound HTTP request to a URL assembled from user-controlled topic text and then fetches whatever URL is injected into the script. Even though the runbook intends arXiv queries, the implementation lacks enforcement that the destination remains the expected arXiv endpoint, which can enable unintended external requests if the URL construction step is subverted or generalized by the agent.
