Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The documentation instructs users to place a required access key in an environment variable and transmit it in requests, but provides no warnings about secret handling, logging, shell history exposure, CI leakage, or safe storage. In a skill context that relies on third-party API access, this increases the chance that credentials are mishandled, copied into prompts, committed to repositories, or exposed in shared terminals and automation.
