Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to use APIFY_TOKEN for API access but does not warn that placing bearer-like secrets in command lines, URLs, or shell-invoked examples can expose them through shell history, process listings, terminal logs, CI logs, and proxy/server logs. In this skill's context, the risk is real because later examples explicitly append the token to request URLs, making accidental credential leakage more likely.
