Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to persist an API token in shell profile files such as ~/.bashrc and ~/.zshrc without warning about local credential exposure, accidental check-in, shell history leakage, or multi-user system risks. While common, normalizing permanent plaintext storage of secrets increases the chance that the token is exposed or reused unsafely.
