If your password leaks from a single service, and I somehow know that you use this tool, I could then try all the combinations of the secret key until the service produces the same password as the one leaked. Now I have your secret key, and can derive your other passwords.
Notice how traditional password managers don't have this problem at all. If a password leaks, it tells you absolutely nothing about the other passwords.