Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs client-side apps to persist a relay token in localStorage and to transmit provider API keys to a managed third-party relay without any prominent warning about trust boundaries, storage risks, token lifetime, or what happens if the relay is compromised. In browser and extension contexts, localStorage is accessible to injected script/XSS, and sending customer API keys to a hosted relay materially expands exposure of sensitive credentials.
