Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill goes beyond mirroring a site by instructing the agent to start a persistent local HTTP server with nohup. That introduces an unnecessary long-lived process and an additional attack surface on the local machine, which is not required to complete the user's core request of downloading files.
