Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The code builds a shell command string for execSync using a user-controlled URL, which creates a command-injection risk if shell metacharacters or quoting edge cases are introduced. In this skill context, the extractor is explicitly designed to process arbitrary external article URLs, so attacker influence over this parameter is expected and makes the issue more dangerous.
