Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs storing an API secret in a local file (`hipc_config.json`) for persistence, but provides no protections such as encryption, restrictive file permissions, secret-store usage, or warnings about credential exposure. If the host is multi-user, the working directory is accessible, logs/backups capture the file, or other skills/processes can read local files, the credential can be stolen and abused to access HIPC resources.
