Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill exposes arbitrary local file write via user-controlled output_file when save_results is enabled. Because the path is not restricted to a safe workspace directory, a caller can overwrite or create files anywhere the process has permission, which is unrelated to the core literature-search function and can be abused for persistence, config tampering, or destructive overwrites.
