Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to write externally derived recommendations into a persistent local MEMORY.md file. That expands the skill from analysis into persistent state modification, which can create prompt-injection persistence, store untrusted or sensitive content locally, and influence future agent behavior beyond the current session.
