Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill repeatedly instructs users to send a Bearer token to a third-party service but does not include any warning about credential sensitivity, storage, rotation, scope, or trust of the remote endpoint. This is dangerous because users may paste production secrets into an unvetted external API workflow without understanding that the token will be transmitted off-host on every request.
