Context-Inappropriate Capability
Medium
- Confidence
- 83% confidence
- Finding
- The skill launches Chrome/Chromium in headless mode with the --no-sandbox flag to render attacker-controlled HTML content. Because the content is generated from untrusted text and markdown and then opened in a real browser process, disabling the browser sandbox increases the impact of any browser engine bug, local file access abuse, or active-content issue during rendering.
