Scope Creep
Medium
- Confidence
- 95% confidence
- Finding
- The setup flow instructs the agent to create `.careerclaw`, extract a resume, and write `.careerclaw/resume.txt`, but the permissions section later describes write access only for `tracking.json` and `runs.jsonl`. This mismatch weakens transparency and guardrail enforcement because the skill writes user-sensitive career data beyond what it claims.
