Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- `evalRawStr` accepts any CDP method name and attacker-controlled JSON parameters, then forwards them directly to `cdp.send`. In the context of a skill meant for interacting with already-open pages, this is unjustified overbreadth and creates a powerful escape hatch that bypasses all higher-level safety assumptions or command restrictions.
