Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to read credentials from a local `.env` file and then use them for authenticated operations, without any consent boundary, minimization guidance, or warning that secrets should not be exposed beyond the intended API call. In an agent-skill context, this is dangerous because it normalizes secret access as part of routine execution and increases the chance that a broader-scoped agent will retrieve and mishandle sensitive tokens.
