Context-Inappropriate Capability
High
- Confidence
- 93% confidence
- Finding
- The report and batch examples expose arbitrary command execution through user-controlled fields such as section.command and item.command. In a demonstration/template skill, this unnecessarily normalizes dangerous patterns and can lead downstream skill authors to embed command execution where safer APIs would suffice, creating command injection and privilege-abuse risk if inputs are not tightly constrained.
