Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The service requires callers to send a raw Anthropic API key to the skill, which unnecessarily expands trust and gives the service access to a sensitive credential unrelated to GitHub fetching itself. If the service is logged, compromised, or modified, user API keys could be stolen or misused for unauthorized model usage and billing.
