Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to automatically run `npm i -g @fly-ai/flyai-cli` if `flyai --version` fails, causing unprompted installation of executable code on the host. For a travel-planning skill, modifying the system environment is not necessary to answer user questions and expands risk to supply-chain compromise, persistence, and unauthorized system changes.
