Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The Android guidance shows configuring long-lived Alibaba Cloud credentials directly in client-side code via environment variables, which is inappropriate for a mobile app threat model. Even if environment variables are only illustrative, this normalizes shipping or injecting powerful credentials into an untrusted client, where they can be extracted and abused to write, read, or tamper with cloud logs.
