Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The viewer loads a sibling `*-data.js` file by creating a `<script>` tag, which executes whatever JavaScript is in that file with the full origin privileges of the page. In this skill, the dialog tree content is supposed to be project data, so treating it as executable code turns any tampering with the data file into script execution, enabling XSS, data exfiltration, or arbitrary actions in the browser context.
