I have often seen claims that doing any kind of crypto in (browser) javascript is dangerous. Does this fall into that trap? How can I safely share the URL to someone without already using an established encrypted communication method? Is the encryption key stored in my browser history?
yes. you can't. and yes.
[1] https://www.nccgroup.trust/us/about-us/newsroom-and-events/b...