Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The skill embeds a concrete API key value directly in setup instructions, which exposes a credential to every reader and encourages reuse of a shared secret. Exposed API keys can be abused for unauthorized API consumption, quota exhaustion, billing impact, and access to any data or actions permitted by that key.
