Context-Inappropriate Capability
Medium
- Confidence
- 83% confidence
- Finding
- The documentation instructs cloning an external GitHub repository at runtime to obtain prompt templates. Pulling remote content into the execution environment introduces supply-chain risk and makes outputs depend on mutable third-party content that is outside the skill's trust boundary.
