Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The README contains what appears to be a live MiniMax API key and explicitly instructs users to place it in environment variables. Exposing real credentials in documentation enables immediate unauthorized use, quota theft, billing abuse, and possible compromise of any data sent through that account. In the context of an LLM integration skill, there is no legitimate need to publish a concrete secret.
