Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to persistently store DATAIFY_API_TOKEN in shell profile files or user environment variables, but it does not warn that the token is a sensitive credential or recommend safer handling such as short-lived session variables, OS secret stores, or avoiding shell history exposure. This increases the chance of accidental credential disclosure through dotfile syncing, local compromise, screenshots, or shared accounts.
