Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The README instructs users to send Bearer tokens and query data to endpoints over plain HTTP, which exposes credentials and potentially sensitive request/response data to interception or modification by any attacker on the network path. In this skill's context, the API serves authenticated crypto-community intelligence and chat summaries, so token theft could enable unauthorized access to private or paid data and tampering with results.
