Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill writes generated files to a hard-coded local directory on the host filesystem without user confirmation, path validation, or disclosure of side effects. Even though the write location is fixed rather than arbitrary, this still creates an unauthorized filesystem-write behavior that can overwrite prior outputs, leak sensitive derived content into predictable locations, and violate least-privilege expectations for an agent skill.
