Context-Inappropriate Capability
Low
- Confidence
- 76% confidence
- Finding
- The skill allows arbitrary http/https URLs as OCR input, which broadens it from local document processing to remote fetching of untrusted content. This can enable SSRF-like misuse, unexpected access to internal resources depending on runtime networking, or processing of attacker-controlled payloads without validation.
