Self-Modification
High
- Category
- Rogue Agent
- Content
Core transport: - `scripts/graymatter_api.sh` - `scripts/gm-self-update` Readiness and auth: - `scripts/gm-login`
- Confidence
- 95% confidence
- Finding
- The skill advertises a self-update mechanism as part of its core transport, which creates a supply-chain and remote-code-execution risk if updates are fetched or applied without strict integrity verification. In an agent skill context, encouraging autonomous update behavior is especially dangerous because it can change executable behavior after installation with minimal user review.
