Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs reading credentials from the user's home directory and persisting an API key to disk, which expands its access to local secrets beyond the core stated function of career assistance. This creates unnecessary secret-handling risk: a compromised or overly broad skill workflow could access, overwrite, or leave sensitive credentials stored in plaintext without user awareness or consent.
