Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill reads API credentials directly from the user's home directory even though its advertised function is feed filtering. While authentication may be needed to access a personalized feed, silently accessing local secrets expands the skill's privilege and creates unnecessary trust assumptions if the user is not explicitly informed.
