Missing User Warnings
Medium
- Confidence
- 73% confidence
- Finding
- The README instructs users to place live API credentials in a .env file but does not warn that these secrets must be protected from source control, logs, shell history, and shared systems. In a skill intended to automate access to social-media accounts, poor secret-handling guidance materially increases the chance of credential leakage and subsequent account takeover or API abuse.
