Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The README explicitly instructs users to capture authentication tokens using an HTTPS proxy, which normalizes interception of sensitive session credentials for a consumer calendar account. For a calendar-management skill, this capability is not necessary when username/password auth already exists, and it increases the chance of credential theft, token reuse, or accidental disclosure of household data.
