Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read cross-session memory and directly modify its own SKILL.md after normal task completion, which exceeds the scope of a business-plan methodology and creates persistent prompt/state poisoning risk. If a user or prior session injects bad guidance into memory or feedback, the skill can silently entrench unsafe behavior across future runs.
