Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The batch mode accepts arbitrary file paths and reads them directly from disk with fs.readFileSync, which expands the skill from markdown formatting into unrestricted local file access. In an agent setting, this can expose sensitive local files if an upstream prompt, tool caller, or untrusted input can influence markdownFiles.
