Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to place a bearer token directly in request headers but does not warn against exposing it via shell history, shared terminals, logs, screenshots, or pasted transcripts. Because bearer tokens are sufficient for account access, accidental disclosure can let others impersonate the user and access profile, chat, and relationship actions on the external service.
