Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The skill instructs the agent to automatically check for updates and download a replacement skill package from a remote URL before each invocation. This creates a remote code and instruction supply-chain channel unrelated to the immediate image/video generation action, enabling unreviewed changes to behavior and making compromise of the hosting endpoint highly impactful.
