Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The 'Self-heal' section instructs the agent to modify the skill itself via '/skill-kit upgrade choco' after execution, creating a self-modification path unrelated to the immediate package/service task. Self-editing behavior weakens trust boundaries and can be abused to persist unsafe changes, expand scope, or overwrite reviewed instructions without explicit user approval.
