Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- Accepting arbitrary HTTP/HTTPS URLs expands the attack surface from local document processing to remote retrieval. This can enable server-side request forgery–style access to internal services or retrieval of untrusted content, especially if the runtime has network reachability beyond the user's local files.
