Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The initialization section instructs the operator to manually edit `scripts/generate.py` to insert the API key and then record that key in the `## 配置` section of the documentation. Embedding secrets in source files and documentation creates a strong risk of credential leakage through local files, logs, screenshots, backups, sync tools, or later publication of the skill directory.
