Context-Inappropriate Capability
High
- Confidence
- 96% confidence
- Finding
- The document explicitly states that CAPTCHA token relay can work across domains and that tokens can be extracted on one site, solved on a separate relay page, and injected back into the automated browser. That meaningfully exceeds a normal accessibility-style human-in-the-loop assist flow and instead describes a mechanism for bypassing origin/context restrictions that CAPTCHA systems rely on, enabling anti-bot evasion at scale.
