Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- When run directly, the script retrieves a runtime admin token and persists it into a local credentials file, creating a durable high-privilege secret on disk. In the context of a skill intended for backend integrations, this expands from transient authentication use into privileged credential materialization, which increases the chance of token theft, accidental commit, local compromise, or reuse beyond the intended session.
