Natural-Language Policy Violations
Medium
- Confidence
- 82% confidence
- Finding
- The skill instructs the agent to auto-apply dark mode based on Israel time, which imposes a specific locale/timezone without user consent and can cause behavior that does not match the user's environment or preferences. While not directly enabling code execution or data theft, hardcoding locale assumptions can lead to incorrect outputs, privacy-framing issues, and policy bypass of user or system defaults.
