Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill includes instructions to retrieve a workspace API token and manually construct an ingest webhook URL, which expands the skill from storage management into credential handling and authenticated endpoint generation. This is dangerous because it encourages exposing a live bearer-style secret in command output and URLs, increasing the risk of token leakage through terminal history, logs, screenshots, or downstream tooling.
