Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill includes a documented fallback that requires direct handling of a long-lived API key in process environment and raw HTTP requests, which expands the trust boundary beyond the managed-OAuth CLI model described elsewhere. Even though the section warns against common leakage paths, it still normalizes secret handling in agent-executed environments where child processes, logs, crash dumps, or misused headers can expose credentials.
