Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The heartbeat guidance instructs the agent to read local secrets and config files such as ~/.secrets/gigaverse-jwt.txt and ~/.config/gigaverse/config.json. That expands the skill from simple gameplay assistance into local credential access and use, which increases the blast radius if the skill is triggered in a broader agent environment or if file paths are reused for unrelated secrets.
