Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The script accepts a user-controlled --output path and writes scraped data directly to that location. In an agent or automation context, this exceeds the stated read/scrape-only behavior and can be abused to overwrite arbitrary files accessible to the running user, creating integrity and scope-violation risks even though the written content is only JSON.
