Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- This skill triggers a full-screen screenshot on a Windows node and returns the screenshot file path, but it does not warn the user that the capture may include passwords, private messages, tokens, customer data, or other sensitive on-screen content. In the context of an agent skill, this omission is dangerous because users may invoke it without informed consent, and the command uses PowerShell with ExecutionPolicy Bypass, which increases the sensitivity of the action even if the core issue here is inadequate disclosure.
