Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The skill says API keys should not be hardcoded, but also instructs that credentials are stored in a local configuration file. That contradiction can normalize insecure secret handling and lead operators to place long-lived Azure credentials in plaintext files, which are commonly leaked through source control, backups, or host compromise.
