Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill is described as controlling a user's local browser via CDP, but the documentation also introduces a remote/cloud browser mode through `BROWSER_USE_API_KEY` and `start_remote_daemon()`. That materially expands the trust boundary and data exposure surface, because browsing actions, page contents, session context, and possibly sensitive user data may be sent to a remote service not disclosed in the core skill purpose.
