Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs operators to use a GitHub PAT from a credential file and the REST API, but it provides no safety guidance on secure sourcing, least-privilege scoping, redaction, or avoiding exposure in logs and subprocess arguments. In a batch-operations skill that touches many repositories, weak credential-handling guidance increases the chance of accidental token disclosure or overprivileged use across multiple targets.
