Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill loads live email credentials from environment variables or a local secrets file and keeps them available for later SMTP/IMAP use. In a skill with no documented business justification, handling mailbox credentials materially expands access to sensitive external systems and enables account misuse if the skill is invoked unexpectedly or repurposed.
