Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script embeds a default proxy token directly in code, which creates a reusable credential for external access if the environment variable is unset. Anyone with source access can extract the token and invoke the proxy service, potentially consuming quota, accessing backend functionality, or impersonating the skill.
