Description-Behavior Mismatch
Medium
- Confidence
- 98% confidence
- Finding
- The skill claims to automate an Electron app via Puppeteer, but the screenshot implementation invokes the macOS screencapture utility on the entire desktop. That can capture unrelated applications, notifications, documents, passwords, or other sensitive host data outside the target app, creating a clear data over-collection risk inconsistent with the stated purpose.
