Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to use unrestricted shell execution as the primary control path, including passing large, model-generated content into shell commands and invoking a local script. This expands the skill from a constrained presentation workflow into arbitrary command execution, creating command-injection and unintended local-action risk if user content, filenames, or future script changes are not safely handled.
