Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The skill stores arbitrary filesystem paths and later expands them into task/reminder content, which extends the skill beyond simple scheduling into local file-reference management. While it does not directly read file contents here, it creates a mechanism for persistent enumeration and disclosure of sensitive local paths into agent prompts or downstream outputs, which can leak environmental details or facilitate follow-on abuse.
