Context-Inappropriate Capability
Medium
- Confidence
- 86% confidence
- Finding
- The skill instructs the AI to directly read authentication material from environment variables and reason about key validity/format. In an adversarial or over-permissive agent environment, this increases the chance of secret exposure to the model layer or accidental disclosure in logs, traces, tool arguments, or user-visible output, which is unnecessary for a category analytics workflow.
