Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- This example builds a shell command with interpolated response text: if the spoken or AI-generated text contains shell metacharacters, quoting breaks and arbitrary commands may execute in the host environment. Because the bridge is specifically designed to turn voice into assistant actions and then speak dynamic output, the input path is plausibly attacker-influenced, making this much more dangerous in context.
