Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The `open_file`/`cmd_open` flow will open any path supplied by the user via `os.startfile`, not just generated `.drawio` files. In a skill context, this broadens capability from diagram generation to arbitrary local file/application launching, which can expose sensitive files or trigger execution through dangerous file associations such as scripts, shortcuts, or executables.
