Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to install software and dependencies from package managers (`pipx`, `uv`, `pip`, venv, and `bdc setup-node`) as part of normal operation. That expands the skill from local document conversion into code/package acquisition with network access and supply-chain risk, which is materially more dangerous than the stated purpose. In an agent setting, automatic installation can also modify the host environment unexpectedly.
