Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The script explicitly disables both certificate validation and hostname verification before sending an authenticated HTTPS request. This allows a man-in-the-middle attacker to intercept or tamper with responses and capture the X-API-KEY, which is especially dangerous because the skill depends on remote content returned from that API.
