Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The script reads an API key from a hard-coded secrets file under a specific Administrator profile before falling back to an environment variable. This creates unnecessary credential access behavior for a simple OCR tool, couples execution to a privileged local path, and can normalize unauthorized use of locally stored secrets if the script is reused in other contexts.
