Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs users to install the CLI by piping a remotely fetched shell or PowerShell script directly into an interpreter. This creates a supply-chain and arbitrary code execution risk because any compromise of the source repository, network path, or script content would execute immediately on the user's machine with the user's privileges.
