Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The instructions direct the agent to handle and persist API credentials in local project files, which expands the skill from image generation into secret management. This is dangerous because a compromised or overly capable skill can capture, store, or misuse bearer tokens, and local persistence in workspace files increases the chance of accidental disclosure, reuse by other tooling, or exfiltration.
