Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- This is a real issue: the skill exposes a public internet-facing webhook endpoint and explicitly recommends logging full request headers and bodies. Webhook payloads commonly contain secrets, bearer tokens, signatures, PII, API keys, or business data, so verbose logging can create secondary sensitive-data exposure in terminal history, log files, or agent outputs.
