Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to obtain credentials from environment variables (`QINGHU_TOKEN` / `QHKIT_TOKEN`) even though the skill’s stated purpose is Bilibili analysis, not secret management. This expands the skill’s privilege boundary and enables unintended secret access and exfiltration risk if the endpoint, prompt, or downstream handling is compromised.
