Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The documentation tells users they can provide their AssemblyAI API key to the agent for configuration, which encourages direct credential disclosure to the skill/operator. This expands the trust boundary unnecessarily and creates risk of secret retention, misuse, or leakage through logs, prompts, or memory.
