Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill claims to search torrents but also includes a separate capability to directly add magnet links into qBittorrent, which crosses from information retrieval into taking an external side effect on the host/application state. That expands the blast radius of the skill: a prompt that appears to request search only could trigger downloads, network activity, disk usage, and interaction with a local service using embedded credentials.
