Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script embeds a live API token directly in source code, which exposes credentials to anyone who can read the file, commit history, logs, or packaged artifact. Hardcoded secrets are easily reused or abused for unauthorized API access, quota exhaustion, billing impact, or account compromise, and the skill's simple data-fetching purpose does not justify shipping the credential in code.
