Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The example reads a bearer token directly from a fixed path in the user's home directory and uses it for an authenticated API call. Even though the goal is alerting, embedding credential access into a monitoring script expands the skill's privilege surface and normalizes unsafe secret handling that could expose or misuse the local gateway token.
