Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The code prepends an external workspace path to Python's import search path, allowing code outside the skill's reviewed package boundary to be imported implicitly. In an agent environment, that creates a supply-chain and code-injection risk: if that directory is writable or replaced, the agent may execute unreviewed code during initialization, even though the feature is described as an optional validation layer.
