Context-Inappropriate Capability
Medium
- Confidence
- 74% confidence
- Finding
- The script provides a direct arbitrary-command execution capability that is broader than a simple benchmark utility and can be dangerous when bundled inside an AI-agent skill. In an agent context, users or upstream prompts may cause the agent to invoke this helper on attacker-chosen commands, turning the skill into a command-execution primitive with access to local files, credentials, and network-reachable resources.
