Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The script disables TLS certificate verification with curl -k while sending an Authorization bearer token and user-supplied content to a remote API. This enables man-in-the-middle interception or tampering, which can expose the API key, alter requests, or forge responses; the video-generation context does not justify weakening transport security.
