Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill instructs the agent to ask users to paste ACCESS_KEY_ID and SECRET_ACCESS_KEY directly into chat, then export them into the session. Collecting long-lived cloud credentials in conversational text is highly sensitive and unnecessary for a normal video-analysis interface, and it exposes secrets to logs, transcripts, downstream tooling, and accidental reuse.
