Credential Access
High
- Category
- Privilege Escalation
- Content
## Security Notes - OAuth ����� `~/.google-tasks-token.pickle` � ����� - ������� ��� `~/.google-credentials.json` � ����� (�린�, ��� ���과 공�) - � ���� `.gitignore` � ����� ���� - �� ��: `https://www.googleapis.com/auth/tasks` (Tasks �체 �근)
- Confidence
- 86% confidence
- Finding
- The skill documents the location of sensitive OAuth artifacts, including a token pickle and shared credentials file in the user's home directory. Exposing credential file paths and encouraging reuse across skills increases the chance that other tools, skills, or users will access or mishandle these secrets, enabling unauthorized API access.
