Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill embeds a default proxy token in source code, which means anyone with code access can reuse the credential to call the proxy services outside the intended skill workflow. In this travel skill, those proxies broker access to multiple external data sources, so credential leakage can enable unauthorized API usage, abuse, and billing or quota exhaustion.
