Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to configure and interact with real cron scheduling, including giving exact shell commands. For a text-only training companion, this expands scope into host-level persistence and task automation, which can be abused to create unwanted scheduled jobs or normalize unsafe operational changes on the user's system.
