Context-Inappropriate Capability
Low
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to source an API token from a local secrets file outside the declared environment variable flow. That expands the skill's effective access to local credential material and normalizes reading secrets from disk, which increases the risk of unintended secret exposure or misuse by downstream agents.
