Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to execute a shell `curl` command supplied via an error message to upload local file bytes. That creates a command-execution bridge from remote/plugin-controlled content into the local shell, and can expose arbitrary local files or enable shell injection if the returned command is malformed or adversarial.
