Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the user to provide a raw API key and store it via a shell command, but it does not meaningfully warn that the key is a sensitive secret, may be persisted in a local config file, may appear in shell history, and should only be entered through trusted channels. Because the skill also uses external providers, compromise of the key could enable unauthorized API usage and billing abuse.
