Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent/user to modify code inside a locally installed third-party CLI under the user's environment. That goes beyond normal publishing actions and creates supply-chain and integrity risk: it can normalize editing executable tooling in opaque cache paths, make future behavior unpredictable, and provide a foothold for unsafe code changes if the instructions are altered or misapplied.
