Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to generate a DOCX and write it to a user-specified path or, by default, the working directory, without requiring explicit confirmation, path constraints, or disclosure of filesystem effects. This can lead to unintended file creation in sensitive or shared locations, overwrite/confusion risks, and makes the skill more dangerous because it performs a side effect beyond pure text generation.
