Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The developer-tools section exposes capabilities such as JavaScript evaluation, DOM inspection, console access, debugger attachment, CDP commands, and screenshots without any warning about arbitrary code execution, introspection, and sensitive data exposure. In context, this is especially dangerous because the skill controls a live Obsidian desktop process, so eval or CDP access could inspect vault contents, manipulate the app beyond note editing, or access secrets visible in the UI or plugin state.
