Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs users to run with `--dangerously-skip-permissions --permission-mode bypassPermissions`, which disables safety checks far beyond what a scraping and local classification workflow needs. If the referenced scripts are compromised or behave unexpectedly, they could modify arbitrary files, exfiltrate data, or perform other unintended actions without user approval.
