Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells the agent to ask the user for email and password when environment variables are absent, but provides no warning, consent language, or safer alternative. This normalizes collection of raw credentials by the agent and can lead to unnecessary exposure of secrets in chat history, logs, or downstream tooling.
