Context-Inappropriate Capability
High
- Confidence
- 97% confidence
- Finding
- API key creation and deletion are privileged security operations that exceed the stated outreach purpose and can be abused to establish persistence, expand access, or disrupt legitimate integrations. An agent with access to these functions could mint new credentials for unauthorized future access or revoke existing keys to cause denial of service.
