Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to modify its own SKILL.md to persist a user-provided proxy setting, creating self-modifying behavior unrelated to the core task of illustrating markdown. Persisting network configuration into the skill definition can silently affect future executions, expand trust boundaries across sessions, and store potentially sensitive infrastructure details on disk.
