Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs loading a locally stored API key from a secrets file and using it in outbound requests, but provides no warning about credential sensitivity, third-party data transfer, or limits on when network access is appropriate. In an agent setting, this can normalize automatic use of local secrets and transmit authenticated requests to an external service without explicit user consent or review.
