Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- `pollImage` accepts any absolute URL and fetches it with the Wavespeed bearer token attached. If an attacker can influence `pollUrl`, this creates a server-side outbound request primitive and may leak the API credential to an arbitrary host via the `Authorization` header. In an agent skill context, this broadens the component from a provider-specific client into a general SSRF-style fetch gadget, which is more dangerous than its stated purpose suggests.
