Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The relay code explicitly includes APP_ID and APP_SECRET in a payload sent to an external relay service, extending trust to another network endpoint that now receives long-lived credentials. If the relay is compromised, misconfigured, or logs requests, an attacker can reuse the secret to impersonate the account and perform broader API actions than intended draft management.
