Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill for temple/travel lookup instructs the agent to install external software globally via npm, which expands its capabilities beyond the advertised purpose and modifies the host environment. This creates supply-chain and environment-integrity risk because a compromised or unexpected npm package could execute arbitrary install scripts or persist on the system.
