Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- This skill goes beyond searching/downloading marketplace content and instructs the agent to execute arbitrary downloaded SKILL.md instructions, including dependency installation and service startup. That creates a remote code execution and prompt-injection chain where untrusted marketplace content can directly cause system changes on the user's machine.
