Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill invokes an external ffprobe binary against user-supplied remote URLs, which expands capability from simple API orchestration into subprocess execution and outbound network access. This can enable SSRF-like behavior against internal or sensitive network targets reachable from the host, and it also increases attack surface through dependency on a local executable.
