Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill documentation directly embeds a usable Bearer API key, exposing credential material to any reader of the skill. This enables unauthorized use of the backend search service, potential quota theft, cost abuse, and use of the key outside the intended agent workflow.
