Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The privacy notice is inaccurate because the FIRMS API key is included directly in the request URL, so more than the stated bounding box, date range, and instrument data are transmitted. Embedding secrets in URLs is dangerous because URLs can be logged by client software, proxies, server access logs, browser history, and monitoring systems, increasing the chance of credential exposure.
