Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to invoke an external Python script via a shell command using raw user input as an argument. That expands the router from passive intent classification into code/tool execution, and if the surrounding runtime does not strongly sandbox or safely pass arguments, it can enable command injection, unsafe tool invocation, or unintended privileged local access.
