Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs automatic cloning of a remote GitHub repository and installation of its Python dependencies at first run via subprocess. This creates a supply-chain and arbitrary code execution risk because unpinned remote code and dependency scripts can execute on the host outside the narrow scope of an OSINT skill.
