Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly auto-saves reports to a local path and creates directories automatically, which causes filesystem modification as a side effect of a simple trigger. This is dangerous because users may invoke the skill expecting content generation only, while the skill persists data to disk and remembers paths across sessions, increasing the chance of unintended writes, privacy leakage, or overwriting files in sensitive locations if a custom path is supplied.
