Description-Behavior Mismatch
Medium
- Confidence
- 81% confidence
- Finding
- The list and delete features operate on system scheduler state rather than a namespaced, skill-owned task registry. On Windows, delete accepts an arbitrary task name, which can remove unrelated scheduled tasks if an attacker can influence the id parameter; on Unix, list/delete expose and manipulate global at jobs without ownership checks.
