Credential Access
- Category
- Privilege Escalation
- Confidence
- 91% confidence
- Finding
The text explicitly documents issuance of bearer access and refresh tokens with meaningful lifetimes but does not pair that with handling requirements. In an agent skill whose purpose is autonomous sign-in and token use, leaked tokens would let an attacker impersonate the agent and call MCP tools until expiry or revocation.
- Content
}
text The access token lasts 45 minutes. The refresh token lasts 7 days. ### 5. Open an MCP session
