Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs execution of a shell command for formatting generated Twitter content, even though the skill’s stated purpose is research and content generation. Introducing command execution expands the attack surface unnecessarily: if user-controlled content is interpolated into the command, it can enable command injection or unsafe local code execution in environments that honor skill instructions.
