Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The script includes a self-update command that downloads a remote tarball from GitHub and overwrites the local skill directory. Even though it performs basic archive path checks, it does not verify a signed release, pinned commit, or trusted checksum before replacing executable code, creating a software supply-chain risk.
