Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The install flow explicitly patches the agent's instruction file so the skill can run autonomously and alter future agent behavior beyond a local data utility. That is a system-affecting modification with persistence, and in this context it meaningfully expands privilege and execution scope without strong user review or containment.
