Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script accepts a user-controlled --file path and resolves it to any absolute path, then uses writeFileSync and mkdirSync to create or overwrite that file. In the skill context, this exceeds the stated purpose of only maintaining a local watchlist and enables arbitrary local file modification if an agent or caller passes an attacker-chosen path.
