Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The onboarding instructs the agent to modify system-wide state by creating a symlink in /usr/local/bin via sudo. That exceeds normal AList file-management needs and can permanently alter the host environment, increasing blast radius if the skill path is replaced or tampered with.
