Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The script executes caller-controlled input through `eval "$APPLY_CMD"`, which allows arbitrary shell execution rather than narrowly applying a configuration change. In a skill advertised as a safe config-rollback helper, this broad execution primitive is especially dangerous because any consumer expecting a constrained config edit path could unintentionally grant full command execution.
