Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill documentation explicitly states that a shared Bearer token for the WeChat mini-program backend is hardcoded in the script. Even if the API is functionally used for read-only queue lookups, embedding and distributing a reusable credential exposes an authentication secret that can be extracted, reused outside the intended client, and potentially abused until rotated. The skill context makes this more dangerous because it normalizes unauthorized access to an unofficial internal backend while claiming 'no API key required,' which may mislead operators into treating the integration as public and low-risk.
