Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly advertises `tandem_network_*` network inspection/HAR capture and `tandem_devtools_send` CDP debug bridge capabilities, which materially expand access beyond normal co-browsing into low-level traffic interception and browser debugging. In the context of a shared browser tied to the user's local profile, these features could expose sensitive headers, cookies, auth tokens, request bodies, and permit powerful browser control primitives if invoked by an agent.
