Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script accesses the system clipboard via `pbpaste` and prints its full contents, which can expose unrelated sensitive local data such as passwords, API keys, private messages, or proprietary text. For a skill whose stated purpose is auditing provided text, silently pulling arbitrary clipboard contents is broader than necessary and increases the risk of unintended data collection or disclosure.
