Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to persistently store API credentials in a local file and source them later. Even with chmod 600, storing secrets in workspace files increases exposure to accidental disclosure, backup leakage, other tools reading the file, or misuse by future sessions.
