Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script intentionally exposes an --eval option that passes arbitrary JavaScript directly into CDP Runtime.evaluate against a live browser session. In the context of a durable Ubuntu browser session with login reuse, this exceeds bounded inspection and can access authenticated page state, DOM content, tokens, or trigger privileged in-session actions on protected sites.
