Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to install recurring routines and even modify system cron, which is a privileged persistence mechanism beyond one-off carousel generation. Persisting execution on the host can surprise users, continue activity after the session ends, and repeatedly trigger networked actions or message delivery. In an agent setting, scheduler installation materially increases blast radius because it creates ongoing autonomous behavior.
