Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The script trusts remote `.files[].filename` values from the Kemia API and writes them directly under `${WORKSPACE}` without validating or normalizing paths. A malicious or compromised server could supply filenames containing `../`, absolute paths, or sensitive workspace-relative targets, causing arbitrary file overwrite outside intended config locations and potentially leading to code execution or persistence when the agent later loads those files.
