Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly exposes macOS UI automation, screenshot capture, screen inspection, and clipboard access, all of which can access sensitive information such as credentials, private documents, tokens, or messages. While these capabilities are the legitimate purpose of the tool, documenting them without any warning, consent guidance, or data-handling caveats increases the risk of unsafe use and inadvertent collection or disclosure of sensitive data.
