Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The README includes an agent-facing installation prompt that instructs the agent to inspect environment-variable availability and prepare a gateway/system restart. Even though framed as setup guidance, this expands the plugin's operational scope beyond memory management into privileged host actions and credential-aware behavior, which can normalize unsafe automation if copied verbatim into an agent session.
