Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The recovery workflow tells the agent/user to install software by piping a remotely fetched script directly into `sh`. This creates a supply-chain and arbitrary code execution risk: if the remote script, hosting path, network path, or repository is compromised, the agent may facilitate execution of attacker-controlled shell commands on the user's machine.
