Context-Inappropriate Capability
Medium
- Confidence
- 81% confidence
- Finding
- The skill instructs the agent to verify and install Node.js and other dependencies on the user's machine, expanding from marketing automation into system modification. Even if operationally useful, this broadens the blast radius: an agent following these instructions could alter the host environment, install untrusted packages, or make changes the user did not expect from a marketing skill.
