Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to handle an API key and even notes that the response includes it, but it does not warn against exposing the key via shell history, logs, screenshots, or pasted examples. In a curl-based workflow, bearer tokens are commonly leaked through terminal history, process listings, shared transcripts, or agent logs, which could let an attacker read or modify the profile and inbox.
