Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The script bypasses the declared AMAP_API_KEY configuration mechanism and instead reads credentials from a fixed file path in the user's home directory. This creates hidden credential coupling, increases the chance of using unintended secrets, and can expose or misuse credentials in environments where that file is present unexpectedly.
