Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The template injects `{{API_KEY}}` into client-side JavaScript, so anyone who opens the generated HTML can recover the credential from page source or browser dev tools. Because the page then uses that key to call a remote API directly, the key can be reused outside the report for unauthorized API access, abuse, quota exhaustion, or data scraping.
