Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to save and export an API key but does not warn against logging, hardcoding, sharing, or storing the credential insecurely. In an agent-skill context, this increases the chance that the key is exposed via shell history, transcripts, notebooks, or downstream tool calls, enabling unauthorized access to the Exuvia account.
