Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill directs the agent to perform a global npm install automatically for a read-only discovery task, expanding system state and trust without necessity or user consent. Installing packages from a registry introduces supply-chain and environment-modification risk, especially because the instruction normalizes retrying installation rather than failing safely.
