Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill goes beyond a narrow heartbeat/task-tracking role by instructing creation and initialization of a separate agent workspace, installing dependencies, and checking for additional core files. This expands the skill's operational scope and gives it authority over broader agent state, which can be abused to plant persistent instructions or modify environments outside the immediate task loop.
