Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The guide instructs agents to send an Authorization bearer token in API requests but provides no safeguards for storing, redacting, or handling that credential. In an agent-skill context, this can normalize unsafe secret handling, increasing the risk that tokens are hardcoded, logged, echoed to users, or exposed through tooling and transcripts.
