Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The MCP server URL embeds the API token in the query string, which is dangerous because URLs are commonly logged by clients, proxies, observability systems, browser/network tooling, and server access logs. This increases the risk of credential leakage and unauthorized use of the Dataify account, especially since the same URL also enables a broad set of remote tools that could consume paid services or access sensitive account-linked capabilities.
