Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill is documented as a query/reporting capability, but it instructs the agent to perform privileged environment modification (`npm install -g`) and to handle credential bootstrapping. Expanding a read/query skill into package installation and auth setup increases the attack surface significantly, because an agent may change the host environment and pull remote code or tooling based solely on skill instructions.
