Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The file contains a hard-coded shared API key that is automatically used when no user-supplied key is present. Embedding a credential in distributed client-side or skill code exposes it to anyone who can inspect the package, enabling unauthorized reuse, quota exhaustion, account abuse, and possible attribution of malicious activity to the publisher's account.
