Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The document embeds a real-looking QVeris API key directly in installation commands and instructs users to export it into their environment. Hardcoded credentials in distributed documentation can be copied by any reader, reused without authorization, and expose the associated account, billing, and data access.
