Context-Inappropriate Capability
Critical
- Confidence
- 99% confidence
- Finding
- A direct JavaScript execution helper enables execution of arbitrary code strings, which is one of the highest-risk capabilities an agent can expose. Combined with the skill's excessive scope, this could be used to run attacker-controlled code, bypass intended task boundaries, or manipulate the surrounding runtime and data.
