Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to generate an Ethereum private key, print it, and persist it locally in a dotfile. That expands the skill from art publishing into custody of financial credentials, creating a serious risk of secret leakage through logs, shell history, backups, multi-tenant hosts, or later prompt/tool access. In this context, the capability is especially dangerous because it is presented as a normal fallback path rather than an exceptional, user-approved wallet flow.
