Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs use of the GITHUB_TOKEN environment variable in outbound GitHub API requests. While this does not directly exfiltrate the token, it normalizes secret access inside a discovery skill and couples user requests to authenticated external requests, increasing the chance of unintended credential disclosure, logging leakage, or misuse if surrounding tooling interpolates commands unsafely.
