Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README explicitly promotes browser login with persistent token storage and also documents environment-variable token usage, but it does not warn users about protecting tokens, file permissions, shell history/process exposure, or avoiding accidental disclosure. In an agent skill context, this increases the chance that credentials are stored or surfaced insecurely during automated use, leading to account compromise for the supported services.
