Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The script accepts a user-supplied --project-file path and then appends attacker-controlled content to that path without restricting it to a detected PROJECT.md in the workspace. In an agentic setting, this expands the write primitive from 'update project context' to arbitrary file modification, which can overwrite or poison other markdown, config, or prompt files reachable by the process.
