Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly states that the access_token is stored in `~/.hermes/auth.json` but does not mention file-permission requirements, local compromise risk, or how sensitive OAuth tokens and refresh tokens should be protected. This can lead users to store reusable credentials insecurely on shared systems or in backups, increasing the chance of account takeover if the file is exposed.
