Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill directs the agent to create a virtual environment and install packages, which modifies the host system beyond simply transforming images into videos. Even if common Python packages are named, package installation and environment creation introduce supply-chain and persistence risks, especially when performed automatically from a conversational trigger.
