Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The manifest executes an external MCP server package via `npx`, which introduces remote code supply-chain risk and delegates substantial behavior to code not visible in this skill file. In the context of a self-evolving, self-upgrading agent with outbound network access, this is more dangerous because the external package can implement broad autonomous actions beyond the narrow user-triggered purpose implied by the manifest.
