Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The documentation explicitly allows proofs against arbitrary external URLs such as staging or other remote hosts, turning a post-implementation demo tool into a general web/API interaction mechanism. In an agent setting, this expands scope from local verification to potentially interacting with sensitive third-party systems, capturing their content, and storing that data in artifacts.
