Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to persist an API token in shell profile files and environment settings without warning about credential exposure, shell history leakage, local multi-user access, or accidental inclusion in dotfile backups/repos. While not overtly malicious, this normalizes long-lived secret storage in places that are commonly copied, synced, or inspected, increasing the chance of token compromise.
