Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs writing an HTML report to the user's Desktop, which requires host filesystem access beyond what is necessary for generating marketing analysis. Unprompted local file creation can violate least-privilege expectations, surprise users, and become a primitive for persistence, clutter, or delivery of active content if the runtime honors such instructions.
