Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to take a user-supplied API key and persist it into user or shell startup configuration, which expands the credential's lifetime and exposure far beyond a one-time invoice check. Persisting secrets in shell profiles or user environment variables can leak them to other processes, future sessions, logs, backups, or unrelated tools. Because the skill processes financial documents, compromise of this API key could enable unauthorized invoice lookups or data access at scale.
