Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The script persists the Bring account email and password in plaintext under the user's home directory, creating a local secret-at-rest exposure. Any local process, backup system, malware, shared account, or accidental file disclosure could recover the credentials and gain full access to the user's Bring account; for a shared shopping-list skill, collecting and storing raw credentials is broader and riskier than necessary.
