Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly tells the agent to check for and reuse a locally saved DATAIFY_API_TOKEN without requiring clear user consent or even a warning that stored credentials will be accessed. In this context, the skill performs external API calls, so silent credential reuse can cause unauthorized actions on the user's third-party account and reduces user awareness of secret handling.
