Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script explicitly disables SSH host key verification with StrictHostKeyChecking=no, which removes protection against man-in-the-middle and host impersonation attacks. In a remote command execution skill, this is especially dangerous because an attacker who can intercept or redirect the connection could capture commands, credentials, or execute commands on an unintended host.
