Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to globally install an npm package automatically if the CLI is missing. This expands behavior from authentication into software installation and executes a third-party supply-chain action without user approval, creating risk of unwanted system modification or package compromise.
