Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to mint, use, and store authentication tokens, including anonymous-token acquisition and persistent session handling. While this supports the service workflow, it expands the skill from simple video editing into credential management, increasing the risk of unnecessary secret handling, token leakage, or reuse beyond the user's informed expectations.
