Ssd 3
- Category
- Not specified by scanner
- Confidence
- 98% confidence
- Finding
The output contract explicitly allows returning raw credentials on request and references disclosure of a one-time temp_password. Exposing access tokens, refresh tokens, api_key, or one-time passwords in assistant responses materially increases the risk of credential leakage through chat logs, screenshots, client telemetry, or prompt injection-driven exfiltration.
- Content
