Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to assess signals such as author publication history and GitHub commit recency, which can push the agent beyond analyzing a supplied SKILL.md into external repository or network investigation. That broadens the skill’s operational scope and may cause unexpected access or behavior inconsistent with a local, static scanner.
