Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill falls back to reading ~/.claude/settings.json to obtain WEREAD_API_KEY, which reaches outside the skill's own configuration boundary into a global user settings file. Even though it only targets a specific key name, this creates unnecessary access to broader user configuration and normalizes secret retrieval from unrelated global state, increasing privacy and credential-handling risk.
