Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The workflow instructs the agent to fetch arbitrary external content and write it to local storage under /tmp without explicit user consent or clear safety constraints. Even though /tmp is transient, downloading attacker-controlled files can enable disk consumption, unsafe downstream processing, or exposure to malformed content from untrusted origins, making this a genuine security concern in an automated agent context.
