Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The script defaults to scanning the user's home directory (`~`) and accepts an arbitrary `--path`, then reads all matching `.md` files from several relative locations under that base. In an agent skill context, this can expose unrelated personal or sensitive markdown content if the tool is invoked with a broad path or without explicit scoping, creating unintended local file disclosure.
