Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs reading an API key from local dotfiles and sending it in Authorization headers to a remote service, but it does not clearly disclose this credential access/transmission to the user at runtime. That creates a real secret-handling risk: users may not realize the skill is pulling sensitive credentials from disk and reusing them for network requests, and the fallback path encourages secret submission through chat.
