Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill embeds a hardcoded internal `X-API-Key` used to access HTM order endpoints beyond ordinary cookie-authenticated portal access. Even if the key was exposed in HTM's frontend, reusing and redistributing it in a third-party automation skill normalizes access to internal order APIs and enables scripted cart/order manipulation if a user session is present, increasing abuse potential and creating legal and security risk.
