Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to obtain and use a Bearer Token as the sole credential for MCP and REST access, but it does not warn that this token is sensitive, should not be hardcoded, and must be protected from logs, screenshots, config sync, and source control exposure. In a setup guide whose purpose is authentication and remote tool access, omission of credential-handling guidance materially increases the risk of accidental token leakage and unauthorized use of the attached Agent Group.
