Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill authorizes execution of external npm packages via npx and may install Chromium, but the skill text does not clearly warn the user that running it can fetch and execute remote code and download a browser binary. This increases the risk of supply-chain exposure and unexpected networked tool execution, especially when invoked from a natural-language request that sounds like a simple document conversion task.
