Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill requires use of `APIFY_TOKEN` but gives no guidance on safe handling, despite later examples placing the token in a URL query string. This increases the chance the credential will be exposed through shell history, logs, process listings, screenshots, or copied commands, leading to unauthorized use of the Apify account.
