Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documentation explicitly lists multiple private-key sources, including a CLI flag, environment variable, and a local config file, and even shows a config example containing a private_key field. In an agent skill context, this materially increases the chance that an automated system or user will expose, echo, store, or retrieve sensitive credentials from insecure locations without strong warnings, especially since the skill is meant to drive terminal interactions.
