Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script hard-codes a reusable proxy credential (`PROXY_TOKEN`) alongside fixed external proxy endpoints, allowing anyone with code access to invoke the upstream SCF-backed travel and map services directly. This can lead to unauthorized service consumption, quota exhaustion, billing abuse, and use of the proxies outside the intended skill workflow.
