Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The script contains a hardcoded API key directly in source code, which exposes the credential to anyone who can read the file, logs, repository history, or packaged skill contents. Because this key is then used to perform authenticated external posting actions, compromise could enable unauthorized posting, abuse of the third-party account, and downstream billing or reputation damage.
