Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The backup/restore code operates on agent memory and configuration artifacts such as MEMORY.md, IDENTITY.md, USER.md, SOUL.md, AGENTS.md, TOOLS.md, skills/, and agents/, which exceeds a narrow 'directory cleaning' scope. In an AI-agent context, these files can contain prompts, memory, tool config, or identity/state, so broad restore capability can overwrite sensitive state or undo security-relevant changes without clear authorization boundaries.
