Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The client exposes a saveKey function that validates credentials and then writes them into a local .env file, expanding a read-only analytics skill into one that persists secrets on disk. For an analytics integration, silent credential storage increases the blast radius of any workspace compromise and creates an unnecessary secret-management surface.
