Missing User Warnings
Medium
- Confidence
- 80% confidence
- Finding
- The script accepts a Telegram bot token from argv or environment and immediately uses it to send data to an external service, with no warning, validation, or guidance on secure handling. In agent/skill contexts, this can lead to unintentional credential exposure or unauthorized outbound actions if users provide sensitive tokens without understanding the network implications.
