Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The README explicitly says the skill includes a built-in free public key while also discussing key-handling hygiene. A built-in shared/public API key is a real security weakness because it invites credential reuse, uncontrolled third-party use, quota exhaustion, abuse attribution to the skill/provider, and possible key leakage through redistribution or logs.
