Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The client includes a capability to persist supplied API credentials into local .env files, which exceeds a read-only market-data skill’s expected behavior and creates a durable secret-handling surface. Persisting secrets to disk can expose them to other tools, users, workspace sync, backups, or later prompt-induced misuse, especially because this skill is framed as a data-fetching utility rather than a credential manager.
