Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation explicitly allows API keys to be supplied via the `api_key` query parameter. Query parameters are commonly logged by browsers, reverse proxies, CDNs, analytics tools, and server access logs, which can expose credentials beyond their intended audience. In a skill that automates write-capable treasury and deployment actions, this increases the chance of credential leakage and subsequent unauthorized API use.
