Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The code hardcodes a live weather.com API key directly in source and uses it to make outbound requests. This exposes a reusable credential to anyone with code access and enables unauthorized API consumption, quota exhaustion, billing abuse, or use of the key outside the intended skill.
