Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly states that a platform API key is embedded in a helper script for immediate use. Distributing live credentials inside a reusable skill enables unauthorized invoice creation and abuse of the associated PayTrigo account if the skill is copied, logged, or inspected. In this payment-processing context, embedded credentials are especially dangerous because the skill is meant for broad bot reuse, increasing exposure rather than limiting it.
