Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly requires long-lived AWS access credentials but provides no guidance on secure handling, least-privilege scoping, storage, or logging avoidance. In an agent setting, this increases the chance that users supply highly privileged secrets insecurely or that the skill is run with overbroad credentials, potentially exposing AWS resources and account data if those credentials are mishandled.
