Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly describes loading arbitrary user-supplied URLs in a real browser, executing page JavaScript, taking screenshots, and extracting the full DOM, but it does not mention trust boundaries, authentication/session leakage, sensitive-content capture, or restrictions on internal/private targets. In this context, the skill can process authenticated pages, personal data, or intranet resources, so the lack of privacy and data-exposure warnings materially increases the risk of unintended sensitive data collection or SSRF-like browsing to protected locations.
