Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly states that `hoist env list` returns real values in JSON mode and also documents `env export`, which can expose secrets such as API keys, database passwords, and tokens to the agent output channel. In an agent context, this is dangerous because secrets may be surfaced to logs, tool transcripts, downstream models, or users without any warning or masking guidance.
