Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill retrieves an admin-scoped credential from an environment variable and sends it on every request to an external service, even though the advertised functionality is only image conversion and QR generation. Using an administrator key for routine user-driven operations violates least-privilege and increases the blast radius if the remote endpoint is abused, logs headers, or the skill is repurposed for unintended API actions.
