Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill falls back to reading a hard-coded workspace .env file to obtain an API key, which expands its access from the explicit environment into local credential files. In an agent-skill context, this is risky because it silently reaches into local secrets storage without clear user consent and normalizes credential-file access beyond the minimum needed.
