Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill documentation instructs users to clone and potentially install/link an external GitHub repository to obtain the `agentgit` CLI, which adds network-based code acquisition and trust in third-party code beyond the stated purpose of validating sub-agent output. In a security-sensitive agent skill, this expands the attack surface materially because the fetched tool could be tampered with, drift over time, or execute unexpected code during use or installation.
