Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to install packages and, if necessary, fall back to system-wide pip installation using flags like --break-system-packages. Modifying the user's global Python environment for a content-generation task can destabilize the host, introduce supply-chain risk from downloaded packages, and create unintended persistence outside the skill's workspace.
