Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The script accepts a user-controlled --output path, converts relative paths to the current working directory, and writes HTML directly to that location without any allowlist, sandbox, or path validation. In an agent/skill context this can overwrite arbitrary files writable by the process, which is unjustified for a divination/report-generation skill and becomes more dangerous because the generated HTML can also embed attacker-controlled question text.
