Context-Inappropriate Capability
High
- Confidence
- 96% confidence
- Finding
- The skill builds a shell command string and executes `npx -y @baozi.bet/mcp-server` through `child_process`, introducing a remote code execution and supply-chain trust boundary inside the agent workflow. Because tool arguments are interpolated into a shell command, malformed input or package compromise could lead to command injection, arbitrary code execution, or execution of unreviewed remote code on the host.
