Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to install software by piping a remote script directly into `sh`, which creates a classic supply-chain and arbitrary code execution risk. This is broader than the stated skill purpose because it authorizes execution of unreviewed code from the network on the host machine, and the danger is amplified by the skill's ability to spend user funds and access local account configuration.
