Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The `serve start --handler <path>` flow resolves a user-supplied path and dynamically imports it, then executes exported handler logic inside the runtime. That gives this skill arbitrary local code execution capability well beyond its marketplace CLI description, which is dangerous in agent settings where tool capabilities may be trusted based on metadata rather than code review.
