Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The script reads per-app `command` values from configuration and executes them via `hearth_ssh_run` on the target host. That creates a general-purpose remote command execution path inside a skill presented as a read-only health check, so a malicious or tampered config can run arbitrary commands rather than only fixed probes.
