Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill tells the operator to collect and pass the user's API key to a downloaded third-party executable, but it does not warn that the key will be exposed to both the CLI process and the remote endpoint. Because the binary is fetched from GitHub Releases or a mirror and then invoked with `-key sk-xxx`, this creates credential-handling risk, including accidental logging, process-list exposure, or malicious/excessive use if the tool or distribution path is compromised.
