Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs users to obtain and use an `lsk_` API key and then publish posts to an external platform, but it does not warn that the credential is sensitive or that invoking the skill causes real external side effects. In an agent setting, this can lead to accidental unauthorized posting, credential mishandling, or users supplying high-privilege tokens without understanding the consequences.
