Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to send an API key in a POST body to an external service and does not include any user-facing disclosure, trust boundary warning, or guidance on secret handling. Even if this is the intended design, transmitting credentials to a third-party endpoint from a generic skill increases credential exposure risk, especially because the endpoint is overrideable via the SCOPEGATE_URL environment variable.
