Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The Farcaster write example instructs callers to place custody and signer private keys into environment variables and then invoke a subprocess to post content. In a social-engagement skill, this expands capabilities from ordinary API usage into wallet-backed actions with sensitive key material, increasing the risk of key exposure, unintended signing, and abuse of external posting authority.
