Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill grants broad exec capability and explicitly suggests curl/WebFetch for external retrieval even though the task is a narrow Reddit research workflow. If an attacker can influence inputs, this opens the door to arbitrary command execution patterns, unsafe shell composition, SSRF-like requests, or unintended access to local/system resources.
