Context-Inappropriate Capability
Medium
- Confidence
- 83% confidence
- Finding
- The skill instructs users to provide a raw API key and then set it via `export` in the shell, which normalizes direct handling of credentials in an interactive session. This can expose the key through shell history, terminal logs, shared sessions, or downstream tooling, creating unnecessary credential-handling risk beyond the search workflow itself.
