Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The script reads KEYAPI_TOKEN not only from the current process environment but also by inspecting the user's shell profile files and extracting a managed block. Accessing local profile files expands the skill's reach into user secrets beyond explicit runtime inputs, which is sensitive behavior even if the goal is convenience. In this skill context, the token is immediately used to authenticate outbound API calls, so unintended secret use is plausible.
