Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script accepts a user-supplied --url and passes it directly to Selenium's driver.get() with no allowlist or scheme/domain validation. In an agent or automation context, this can be abused for server-side browsing/SSRF-style behavior, access to internal web interfaces, or navigation to hostile pages that exploit the browser/runtime, which is riskier than the stated narrow purpose of scraping Weibo hot-search pages.
