Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill constructs filesystem paths directly from the user-controlled province value when reading and writing history files. If an attacker can supply crafted province names containing path traversal sequences, they may read or overwrite unintended files relative to the skill directory, making this a real file access vulnerability despite the feature's benign purpose.
