Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to ask users to paste cloud access credentials into chat and then export them as environment variables. Collecting high-value secrets through chat for an image beautification workflow is unjustified and creates a direct path to credential theft, accidental retention in logs, misuse by the agent, or compromise of the user's broader cloud account.
