Context-Inappropriate Capability
Medium
- Confidence
- 83% confidence
- Finding
- The script performs an unsolicited outbound network request to GitHub for self-maintenance, which is unnecessary for the stated eval/testing purpose and expands the trust boundary. Even though it only fetches metadata, such behavior can leak environment information, introduce nondeterminism, and create a channel for remote influence over local workflow decisions if the remote content or URL is changed.
