Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs reading provider credentials from `~/.kimi-code/config.toml` and handling `api_key` values without an explicit consent gate or warning, which risks unauthorized access to secrets beyond what the user intended to share. Because the skill also uses those credentials for outbound network requests, accidental activation or over-broad execution could expose or misuse sensitive provider access.
