Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- This skill intentionally provides two plaintext secret exfiltration paths: `--get --raw` writes decrypted secrets to stdout, and `--inject` substitutes decrypted secrets directly into arbitrary command strings and emits the result. In an agent environment, stdout, command strings, shell history, process listings, logs, and downstream tools are common leakage surfaces, so a 'secure secrets store' that also acts as a plaintext secret emitter materially increases exposure risk.
