Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- This section instructs the user to copy an API key into a second credential store and bring up a network-connected provider daemon, but it does not clearly warn that this creates persistent local credentials and exposes the host to inbound remote work over a WebSocket connection. In a skill context, that omission matters because users may not realize they are enabling continuous remote connectivity and storing reusable secrets on disk.
