Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents that local config stores Wilma session credentials for accessing student data and later describes saving and auto-using TOTP secrets, but it does not pair this with clear warnings about credential sensitivity, local file protection, or the risk of exposing secrets to the agent context. In an agent-integrated skill that handles minors' educational records, normalizing persistent session and MFA-secret storage without safeguards materially increases the chance of credential theft, unauthorized account access, and privacy violations.
