Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs users to authenticate with an API token or session cookie but does not include any warning about secure handling, storage, or non-disclosure of those credentials. In an agent context, this increases the risk that a user may paste secrets into prompts, logs, or third-party tools, enabling account takeover or unauthorized API use if the credentials are exposed.
