Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The documentation tells operators to silently fall back to a hardcoded API key when the user's credential is absent. Hardcoded shared credentials are unsafe because they bypass normal authentication expectations, encourage unauthorized external service use, and can expose users to rate-limit abuse, service misuse, or trust confusion about whose account is being used.
