Context-Inappropriate Capability
Medium
- Confidence
- 82% confidence
- Finding
- The README explicitly advertises an automatic skill creation capability for an AI assistant enhancement layer, which implies the system may be able to modify or extend its own behavior. In an agent-skill context, self-extension features materially increase attack surface and can enable persistence, unsafe code generation, or unauthorized capability expansion if not tightly sandboxed and explicitly consented to by the user.
