Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The skill instructs users to place a live API token in an environment variable and states the script will automatically send it as a Bearer token, but it does not warn that the token is sensitive or should not be echoed, logged, pasted into transcripts, or set in shared environments. In agent and shell-assisted workflows, this omission can lead to credential leakage through terminal history, debug output, screenshots, or shared session logs.
