Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill constructs a browser link that embeds the bearer token directly in the URL query string. URLs are commonly exposed via browser history, logs, referrer headers, screenshots, and link sharing, so anyone obtaining that URL may gain access to the user's NemoVideo session and task context.
