Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill launches an external Python script from a hard-coded path and treats it as part of the processing pipeline without any trust boundary, integrity check, or output validation. This creates a dangerous cross-skill execution dependency: if that script is replaced, modified, or behaves unexpectedly, the PDF-analysis workflow can execute untrusted code or ingest adversarial output.
