Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill includes a post-execution instruction to run `/skill-manager upgrade omz`, which expands its behavior from Oh My Zsh configuration into self-modification. Allowing a skill to trigger its own upgrade based on conversation content creates a pathway for unreviewed changes to future behavior, increasing supply-chain and persistence risk.
