Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The documentation explicitly instructs copying screenshots generated during QA into `/var/www/html/qa/`, making potentially sensitive application data web-accessible. Because the script captures full-page screenshots after navigation, form filling, and authentication flows, those images may contain tokens, PII, internal pages, or security-sensitive states that should not be published.
