Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill presents itself as a simple calculator service, but the required secret is named `XINIUDATA_MCP_TOKEN`, which suggests a different backend or reused credential context. This mismatch can mislead operators into supplying an unrelated sensitive token to an internal HTTP endpoint, increasing the risk of credential misuse or accidental exfiltration.
