Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The documentation includes a realistic Ghost Admin API key in a shell export example, which normalizes embedding sensitive credentials directly in docs and configuration files. Even if the key is illustrative, it can be mistaken for a usable secret, copied into insecure storage, or encourage unsafe credential-handling practices for an API that can modify and delete site content.
