Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The script reads an API key from the environment and uses it to send user-supplied research tasks to an external service. That is a real security concern because it enables outbound data transfer and credential use without any visible validation, consent flow, or restriction on what topic/chat data may be transmitted.
