Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The code walks up to the workspace root and loads a .env file, then implicitly consumes ETHERSCAN_API_KEY. For a read-only blockchain analytics skill, reading workspace-scoped secrets is broader than necessary and creates unnecessary credential exposure if the skill is reused in a larger environment containing unrelated secrets.
