Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs users to pass an API key directly as a command-line argument, which can expose the secret through shell history, terminal logging, audit trails, and process listings visible to other local users or monitoring tools. Because this is a setup workflow for a real provider credential, the context makes the issue more dangerous rather than less: users are likely to paste a live API key exactly as shown.
