Context-Inappropriate Capability
Low
- Confidence
- 93% confidence
- Finding
- The skill reads a proxy token from the environment even though the code implements only local, static data lookup and never needs authentication or network access. Unnecessary credential access increases exposure of secrets and creates latent risk if future code, logging, error handling, or prompt leakage surfaces the token.
