Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The documentation includes a hosted remote-script bookmarklet that can load arbitrary JavaScript from `YOUR_HOST` into any visited page. That creates a code-injection and supply-chain risk well beyond the stated self-contained annotation use case, especially because users may run it on sensitive internal or third-party sites.
