Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to use provided Auth0 credentials and write them to a local `.env` file without an immediate user-facing warning, consent step, or preference for safer secret stores. Even though `.env` is common in development, agent-driven handling of client secrets increases the chance of accidental disclosure through workspace files, logs, shell history, or later commits.
