Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The setup flow instructs the agent to silently execute a readiness command that can detect and auto-bootstrap local dependencies before any explicit user-facing consent. For a character-image-generation skill, broad local command execution and environment mutation exceed the narrow expected scope and create risk of unexpected code execution or package installation in the user's workspace.
