Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill embeds and instructs use of a hard-coded bearer token as a fallback credential. Shipping a reusable API key inside public skill documentation creates credential leakage, encourages unauthorized reuse, and makes abuse attribution and revocation difficult; it is not necessary to fulfill the paper-search purpose if users can supply their own key or use a brokered service.
