Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The documentation discloses a hardcoded internal Dify base URL and a live-looking API key, which is a real secret exposure and expands the skill's effective scope into credential distribution. Anyone with access to the skill can reuse the credential to query internal systems, potentially exposing knowledge-base contents, workflows, and other sensitive data.
