Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The template explicitly instructs the agent to execute a local shell script for scoreboard operations. Even though the intended use is benign, this expands the agent's capabilities from moderation into command execution, and several arguments to the script are derived from user-controlled debate content such as participant names, topics, and formats. If the surrounding runtime does not strictly sandbox and safely pass arguments, this creates command-invocation and data-integrity risk.
