Context-Inappropriate Capability
High
- Confidence
- 96% confidence
- Finding
- The code runs a user-configured string via `sh -c` whenever new mail arrives, creating arbitrary shell execution triggered by external network events. In a mail client context, this is dangerous because any email sender who can cause message delivery can trigger local command execution, and use of a shell amplifies risk if this feature is later combined with message-derived data.
