Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The code enumerates default Chrome user-data directories, reads DevToolsActivePort files, inspects running processes, and attaches to existing Chrome remote-debugging sessions. That gives the skill visibility into and control over a user's live browser context, including authenticated tabs and profile state, which exceeds a simple URL-to-markdown capture need and can expose sensitive data from logged-in sessions.
