Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The function performs live outbound HEAD requests to user-supplied URLs as part of 'validation', which creates network side effects unrelated to a spec-writing or reverse-spec skill. This can enable SSRF-style access to internal services, leak network metadata, and cause unintended external traffic from the host environment.
