Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The manifest declares four sensitive credentials, including API keys and a signing key, even though the skill is explicitly marked as a non-executable bundle with install: none and executable: false. Requesting privileged secrets without a runtime need violates least privilege and creates unnecessary exposure: users may disclose billing, wallet, or signing credentials to content that only provides guides/templates.
