Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The library will fetch any user-provided http/https URI via requests.Session.get() with no allowlist, scope restriction, or explicit consent check in this code path. In the context of a writing/style-analysis skill that is supposed to process local user materials, this broad network-fetch capability can be abused for unintended outbound requests, including access to attacker-controlled content or internal network targets if upstream callers pass untrusted URLs.
