Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The script persists KEYAPI_TOKEN into the user's shell profile, modifying startup files outside the immediate Reddit-analysis task. While likely intended as a convenience setup helper, this creates long-lived credential exposure risk: the token is stored in plaintext in a broadly loaded profile file, may be inherited by future shells/processes, and the script writes to user environment configuration automatically.
