Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a general VueUse helper, but it authorizes automatic use of powerful browser and device APIs far beyond harmless reactive utilities. That creates a pathway for an agent to introduce privacy-sensitive or capability-expanding code such as script injection, local file access, Bluetooth, notifications, screen capture, and worker execution without clear user intent or safety gating.
