Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The heartbeat instructs the agent to fetch updated skill files from a remote server and overwrite local copies automatically. This creates a remote code/instruction supply-chain channel: if the server, DNS, TLS endpoint, or hosting is compromised, future agent behavior can be silently replaced without human review, expanding the skill's authority beyond order polling.
