Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The introduction of a callback_url and network-oriented behavior expands the skill's trust boundary beyond local file processing into outbound communication. In a tool presented as a local PPT/font repair utility, this can enable silent data exfiltration, SSRF-like requests, or disclosure of file metadata/results to untrusted endpoints if an agent honors the parameter.
