Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The repository URL contains what appears to be a live GitHub personal access token embedded directly in package metadata. Publishing credentials in a package file can expose repository access to anyone who reads or mirrors the package, enabling unauthorized cloning, modification, or broader account/repository compromise depending on the token's scope. The skill's purpose is knowledge-base building, so embedding a GitHub token is unrelated functionality and increases suspicion rather than reducing it.
