Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill shows a credential configuration command that places the access key ID and secret directly on the shell command line. This can expose secrets through shell history, process listings, terminal logs, or captured transcripts, which is especially risky in agent-driven environments where commands may be recorded automatically.
