Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The script exposes a generic capability to execute any Composio action specified at runtime, with no allowlist, purpose restriction, or validation of which remote operations are permitted. In an agent skill context, this is dangerous because it can be repurposed to trigger sensitive third-party actions such as sending messages, modifying documents, or accessing external services beyond an intended narrow use case.
