Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The heartbeat routine instructs the agent to self-update by downloading remote markdown files and overwriting local skill files without integrity verification, pinning, or user approval. That creates a supply-chain path where whoever controls the remote content or transport can silently change future agent behavior, which is much more dangerous than ordinary social-network API use.
