Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The code accepts arbitrary http/https URLs for reference_audio and fetches them server-side. This enables SSRF-style behavior, allowing a user to make the host contact arbitrary internal or external endpoints and store the response as a local file, which is more dangerous in a skill that already has network and filesystem permissions.
