Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The legacy HTTP fallback consumes a raw authentication token from the environment and manually constructs browser-like authenticated requests. This bypasses the safety and visibility benefits of the official CLI login flow, increasing the risk of accidental token misuse, unauthorized API calls, and operational handling of long-lived secrets inside generic process environments.
