Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to persist a long-lived API key in a predictable plaintext file under the user's home directory without any warning, access-control guidance, or minimization. If the local machine, logs, backups, or other tools can read that file, the credential could be stolen and used to impersonate the agent against the external service.
