Context-Inappropriate Capability
High
- Confidence
- 95% confidence
- Finding
- The skill is presented as prompt-injection protection, but it also instantiates and starts an autonomous auto-update/hardening subsystem at construction time. In a security-sensitive agent context, hidden side effects that can change system behavior or fetch/apply updates expand the trust boundary and create a path for unintended network access, configuration drift, or remote code/logic changes unrelated to input sanitization.
