Description-Behavior Mismatch
High
- Confidence
- 94% confidence
- Finding
- The README advertises extensive capabilities beyond basic Android UI automation, including access to location, contacts, calendar, photos, SMS, phone calls, installed apps, and broad file access. Even though this is documentation rather than executable code, documenting and normalizing such broad data-access scope creates a real security concern because it signals a high-privilege skill design that could be used for surveillance, data exfiltration, or account abuse if enabled.
