Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The interceptor retrieves executable workflows from a remote cloud service and runs them locally after only a validation check, creating a remote-action supply chain risk. In an automation/browser agent context, this is dangerous because a compromised or malicious cloud response could drive sensitive browser actions, exfiltrate data, or perform unintended transactions without explicit user approval.
