Context-Inappropriate Capability
High
- Confidence
- 96% confidence
- Finding
- The skill exposes arbitrary command execution even though its stated purpose is lightweight RSS aggregation and report generation. In an agent environment, unnecessary exec access materially increases the blast radius: prompt-influenced inputs or future modifications could lead to filesystem changes, data exfiltration, or execution of attacker-chosen shell commands unrelated to RSS fetching.
