Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The module reads endpoint, username, and password from a local TOOLS.md file in the user's workspace, effectively harvesting credentials from a file outside the immediate API-client responsibility. In an agent/skill context, this is more dangerous because the code can silently access secrets available in the runtime environment and use them to authenticate to external systems without explicit user approval.
