Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The README explicitly instructs users to manage a remote ground-truth server over SSH, Docker, and Conda. That extends the skill from local code migration into remote system access and process control, which increases attack surface and could lead to unintended changes on external machines if followed blindly.
