Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs use of pyautogui to move the mouse and click fixed screen coordinates, which gives the workflow arbitrary desktop UI-control beyond the stated purpose of asking an AI question. In the context of a logged-in browser, this can misfire on different screen layouts or be repurposed to click sensitive UI elements, enabling unintended actions in authenticated sessions.
