Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The script allows a config file to override endpoints with arbitrary URLs, which expands the skill from a bounded speed-test tool into a generic network fetcher. In an agent context, this can be abused for unintended outbound connections, internal network probing, or contacting attacker-controlled hosts while appearing to perform benign speed tests.
