Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill directs the agent to execute a local Python/Pillow script on embedded image data during document reading, which expands behavior from parsing/revision into arbitrary local tool execution. Even though the sample script is bounded to image compression, normalizing code execution from untrusted document content increases attack surface and can lead to unsafe handling of adversarial payloads or environment-dependent abuse.
