Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a data-query/tracking capability, but it also instructs the agent to generate an Ed25519 keypair, collect an API key from the user, and persist both credentials locally. That expands the skill from read-only querying into credential provisioning and secret handling, increasing the attack surface and making accidental disclosure or misuse of authentication material more likely.
