Context-Inappropriate Capability
Medium
- Confidence
- 82% confidence
- Finding
- The code imports a sensitive client key from OLVID_CLIENT_KEY in the process environment and then may persist it into the plugin configuration. This expands secret-handling behavior beyond simple interactive channel setup and can cause credential exposure if config files are stored insecurely, logged, synced, or inspected later.
