Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to run local shell commands that modify MCP configuration and install a skill from the network, even though the declared purpose is chat connectivity. This expands the skill's authority from using an existing communication tool to changing the host environment and persisting code/configuration, which creates supply-chain and local-environment risk if followed automatically.
