Context-Inappropriate Capability
High
- Confidence
- 97% confidence
- Finding
- The skill automatically installs missing npm packages by invoking `execSync` with `shell: true`, which mutates the host runtime and executes external code without user approval. Even though the package names are currently hardcoded, this behavior creates a supply-chain execution path and expands the attack surface in a tool whose purpose is local file retrieval, not environment modification.
