Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The injected API exposes execJS(script), which allows arbitrary JavaScript execution in the context of whatever page the agent is controlling. That capability goes beyond the stated DOM extraction and interaction purpose and can be used to read sensitive page data, tamper with application state, or invoke privileged in-page actions, making the skill materially more dangerous.
