Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill documentation instructs executing local Python code and invoking another skill's script from a filesystem path, which extends behavior beyond declarative image/video generation into arbitrary local code execution. Even though the embedded code is aimed at image post-processing, this pattern increases attack surface because skill content is untrusted and can normalize running shell/Python snippets with workspace and local filesystem access.
