Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The example explicitly shows extracting an authentication token from browser cookies and exporting it into a shell variable. That enables easy exfiltration, reuse, or accidental disclosure of live session credentials outside the browser automation context, which goes beyond ordinary testing examples and lowers the barrier to credential theft or misuse.
