Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The QR code example goes beyond passive data transformation and performs host modification by invoking Homebrew to install software automatically. In an agent skill context, this creates unnecessary system-change capability and increases risk of unreviewed package installation, especially if triggered without explicit user consent.
