Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to run `npm install -g better-sqlite3` if a dependency is missing, which grants the skill system-wide package installation capability unrelated to a narrowly scoped bookkeeping action. Global package installation modifies the host environment, can introduce supply-chain risk, and creates persistence beyond the current task, making this an unsafe escalation of privileges/capabilities.
