Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs use and storage of a Shopify Admin access token but does not warn that this credential grants privileged access to live store resources and must never be exposed in prompts, logs, screenshots, or responses. In an agent context, omission of credential-handling guidance increases the chance of accidental secret disclosure or unsafe transmission to untrusted destinations.
