Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill includes direct scheduler management commands that create and remove cron jobs using event names interpolated into command arguments. In this context, reminder management can justify scheduling, but exposing raw cron administration without clear validation, escaping, or least-privilege boundaries increases the risk of command/argument injection or unintended persistent task creation.
