Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents extraction of all browser cookies, including httpOnly cookies, via CDP. That enables session-token theft and account hijacking, and it exceeds ordinary page automation because httpOnly cookies are intentionally protected from page JavaScript. In the context of remote browser control on a real phone, this materially increases the sensitivity of the capability.
