Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to export a live API key directly into the shell without any guidance on least-privilege handling, avoiding command history leakage, or preventing accidental exposure in logs and shared environments. In an agent/tooling context, credential mishandling can lead to unauthorized API use, quota theft, and lateral exposure if the environment is reused.
