Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The documentation reveals a concrete local filesystem path to a file that stores a Slack bot token, effectively advertising where sensitive credentials reside. Even though the token value is redacted, exposing the path lowers the effort needed for credential discovery or targeting, especially in a restoration skill that may already operate with elevated local access.
