Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- This script reads arbitrary clipboard contents via `pbpaste` and prints them to stdout, which can expose sensitive data the user copied for unrelated reasons, such as passwords, tokens, private messages, or internal documents. For a skill whose stated purpose is polishing collaboration messages, silent clipboard access is broader than necessary and increases the chance of unintended data collection or disclosure.
