Description-Behavior Mismatch
Medium
- Confidence
- 87% confidence
- Finding
- The skill is presented as a macOS UI automation utility, but the referenced documentation expands into autonomous-agent, MCP server, and generic tool/run capabilities that go beyond narrowly scoped UI interaction. That mismatch increases the chance an agent will invoke broader execution features than users expect, weakening least-privilege assumptions and making abuse or accidental overreach more likely.
