Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The installation guide instructs the agent to invoke another skill to create this skill and to alter the current agent's USER.md, which expands the skill's authority beyond voice reply into self-propagation and persistent configuration changes. This is dangerous because it can modify agent behavior without clear user consent, creating a supply-chain style persistence mechanism inside the agent configuration.
