Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The document contains a hardcoded third-party API key in plaintext, which is a real secret exposure. Anyone with access to this file can reuse the credential to consume the external service, incur charges, access associated account resources, or pivot into other connected workflows if the key is overprivileged.
