Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to save a generated HTML file into the user's workspace or a specified path without requiring confirmation. Any agent action that writes files on the user's behalf should be gated by explicit consent, because unexpected file creation can overwrite existing work, place content in sensitive locations, or be abused in prompt-injection chains to persist untrusted output.
