Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The client loads an API key from the environment but silently falls back to a hardcoded credential embedded in source. Hardcoded secrets are recoverable by anyone with code access and can enable unauthorized use of the upstream service, quota abuse, impersonation of legitimate clients, and difficulty rotating compromised credentials.
