Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The scanner extracts untrusted .skill archives to disk with zipfile.extractall() before analysis. Even though this is for scanning, archive extraction is a real file-write operation and, without validating member paths, can expose the host to zip-slip style path traversal or unintended overwrites outside the temporary directory.
