Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The skill explicitly permits storing a live API key in TOOLS.md, which is typically documentation or repository content rather than a protected secret store. That guidance materially increases the chance of credential leakage through version control, logs, sharing, or downstream agent/tool exposure, enabling unauthorized access to BlueColumn data and services.
