Intent-Code Divergence
Low
- Confidence
- 78% confidence
- Finding
- The documentation asserts only public-data access and no privacy-data involvement, yet example URLs include xsec_token query parameters that may be sensitive session- or access-associated values. This can mislead users into sharing tokenized URLs without understanding their sensitivity, potentially exposing account-linked access artifacts in logs, shells, or saved files.
