Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The script accepts Stremio credentials from environment variables, which are commonly exposed to child processes, shell history wrappers, CI logs, crash dumps, and process-inspection tooling depending on how the script is launched. In an agent/automation context, this broadens the credential exposure surface beyond an interactive prompt and is not strictly necessary for the stated consumer-facing skill purpose.
