Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The screen capture and OCR routines can read arbitrary visible desktop content, including passwords, messages, tokens, documents, and other sensitive data, without any consent prompt, scoping, or disclosure. In an agent skill that automates the desktop, this materially increases surveillance and data-exfiltration risk because the code can observe whatever is on screen, not just app-owned content.
