The screenshot shows a macOS Save As window for a Write.as document.
The filename displayed is “Editing 7t9s43yv8fq5b — Write.as”, with Downloads selected and HTML text (.html) as the format.
The document also contains the labels #NSA, #CIA, #DC, and #DOD.
The screenshot alone does not show how those filename characters or labels were produced, or whether they are connected.
It therefore is not enough to determine what process or person, if any, is responsible.
For a practical check of the Mac, EtreCheckPro would be useful because it can provide an overview of the hardware, operating system, installed software, startup items, background processes, and other configuration information.
It should be treated as diagnostic information, not as proof that unauthorized access has occurred.
I would run EtreCheckPro and avoid deleting or changing anything it flags until the results have been reviewed. Apple's System Report can provide additional hardware and software information, and Login Items & Extensions can be checked for items that open automatically or run in the backgr
If you are investigating unexpected changes on the Mac, Apple provides Login Items & Extensions under System Settings >> General, where you can review items that open automatically and apps permitted to run in the background. (Apple Support)
Apple also documents how macOS controls applications' access to files and its Automation permissions. (Apple Support)
Apple: Login Items & Extensions
Apple: Controlling app access to files in macOS
Apple: Shortcuts privacy settings on Mac