Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The script sources a plugin-wide .env file into the current shell, importing every variable and any shell syntax contained in that file. For a simple browser-automation task, this is broader than necessary and creates risk of unintended secret exposure or code execution if the .env contents are modified or not strictly data-only.
