Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The report template injects user-controlled fields such as product name and direction directly into HTML without escaping. If any upstream caller passes HTML or JavaScript payloads, the generated report becomes an XSS-capable document that will execute in the viewer's browser or webview, which exceeds the skill's stated purpose of producing a passive decision report.
