Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly falls back to using ANTHROPIC_AUTH_TOKEN for a DeepSeek API request, which repurposes a credential intended for a different service. This creates a cross-service secret misuse risk: the skill can transmit a sensitive token outside its stated purpose, potentially leaking or misusing credentials if the token is valid for another endpoint or if operators assume it will never leave the Anthropic context.
