Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README instructs users to place the Tavily API key directly in a command-line URL, which can expose the credential through shell history, terminal logging, process listings, and copied configuration snippets. Because this skill is specifically about interacting with an external service that requires an API key, the unsafe setup guidance is more dangerous in context: users are likely to follow it verbatim and leak a live secret.
