Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill defines a server-pushed `command` message and instructs the agent to return a `command_result`, but it provides no constraint on what commands are safe, no validation requirements, and no prohibition on local tool or shell execution. In an agent-skill context, this creates a dangerous remote-instruction channel that can be interpreted as authorization to execute arbitrary actions beyond the documented messaging/news/social workflows.
