Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs operators to read `appId` and `appSecret` from a local config file using shell commands, which encourages direct access to broader local secrets during routine use. In an agent context with `read`, `grep`, and `exec` capabilities, this expands the skill from file sending into credential discovery and increases the risk of unintended secret exposure in logs, prompts, or downstream command output.
