Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs use of APIFY_TOKEN but does not warn against placing secrets on the command line or exposing them in logs, shell history, or screenshots. In this document, later examples pass the token in URL query strings, which increases the chance of credential leakage through terminal history, process inspection, proxy logs, and copied transcripts.
