Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The skill instructs users to place GitCode access tokens directly in URL query strings for API calls. Query-string tokens are commonly exposed through shell history, proxy/server logs, browser history, process listings, and diagnostic output, so this guidance can directly leak credentials.
