Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The status script reads the agent private key from configuration and uses it to derive the agent address, even though a read-only status check does not need signing capability. This unnecessarily expands the secret exposure surface: any user able to invoke or inspect this script path may trigger handling of a sensitive key, and compromise of the script environment or logs would have more severe consequences than a purely public-data status query.
