Context-Inappropriate Capability
High
- Confidence
- 97% confidence
- Finding
- The skill explicitly passes --trust-remote-code when loading a user-specified local or remote model, which permits execution of model-supplied Python code inside the container. Because the model source is user-controlled and may come from HuggingFace or ModelScope, this turns a verification workflow into arbitrary code execution with the container's privileges, potentially enabling data exfiltration, credential theft, or lateral movement.
