Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs the skill to obtain an authentication token from an environment variable or config file but provides no warning about secret handling, storage risks, or accidental disclosure. In a skill context, silent credential loading is dangerous because the agent may act with the user's forum identity and sensitive tokens may be exposed through logs, misconfiguration, or overly broad file access.
