Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The `stamp` command writes to an arbitrary user-supplied path with no confirmation, backup, or path restrictions, and replaces the file contents via a temporary file and `mv`. In an agent or automation context, a mistaken or manipulated filename could corrupt important project files, inject content into sensitive text/config files, or break downstream tooling that consumes those files.
