Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill embeds a live external MCP endpoint with a hard-coded API key directly in documentation. This exposes credentials to anyone who can read the skill and enables unauthorized use of the external service, while also creating an unreviewed data egress path for user queries to a third-party endpoint.
