Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The script hardcodes a proxy access token directly in source code, which creates a secret-exposure risk if the skill is shared, logged, or inspected by unauthorized parties. Anyone who obtains the code can reuse the token to access the external proxy, potentially consuming quota, abusing the backend, or impersonating this skill's traffic.
