Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill embeds a live-looking API token directly in documentation and explicitly instructs reading credentials from SECRET.md. Hard-coded secrets are highly sensitive because they can be copied, reused, or harvested by anyone with access to the skill file, enabling unauthorized access to the user's flomo data and any actions permitted by that token.
