Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly enables control of the user's real Chrome profile and existing logged-in sessions, which can expose sensitive data, session-bound actions, and private content if invoked without strong user awareness and consent. Although this appears to be the intended functionality rather than overtly malicious behavior, the documentation lacks explicit privacy and data-exposure warnings, making accidental over-collection or unauthorized actions more likely.
