Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents `gccli auth export` and `gccli auth import <token>` and even suggests piping credentials to a file or copying them to another machine, but it does not warn that the exported token is effectively a bearer credential. That omission can lead users or downstream agents to store secrets insecurely, leak them via shell history/files, or transfer them to less-trusted systems, enabling account takeover of Garmin data.
