Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The instruction to "download and use whatever fonts are needed" expands the skill from local art generation into network-enabled retrieval of arbitrary external resources. That creates unnecessary supply-chain and data-exposure risk, since a compromised or untrusted font source could deliver malicious content or cause the agent to contact external systems without a user-justified need.
