Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README explicitly states that the skill captures screenshots and DOM snapshots from arbitrary live websites, but it provides no warning about privacy, sensitive data exposure, authentication state, or how captured content is stored and handled. In an agent context, this is risky because users may point the tool at internal apps, logged-in pages, or sites containing personal or confidential information, causing unintended collection of sensitive visual and DOM data.
