Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill instructs users to obtain and use an API key but provides no guidance on protecting it from shell history, terminal logs, screenshots, or accidental publication. In agent/tooling contexts, credentials are often copied into scripts or command lines, so omission of basic secret-handling advice materially increases the chance of credential leakage and unauthorized inbox/profile access.
