Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to read and use the GITHUB_TOKEN environment variable to authenticate outbound GitHub API requests. This creates a credential-handling path inside a third-party skill and normalizes using a potentially sensitive token for untrusted workflow logic, increasing the risk of secret exposure, misuse, or unauthorized network actions if the skill or downstream content is adversarial.
