Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to obtain and use an `auth_token` but does not warn that it is a secret, should not be logged, shared, or hardcoded. In an agent-skill context, omissions around credential handling increase the chance that tokens are exposed in transcripts, code, or downstream tools, enabling account misuse.
