Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to export and use a bearer API key but does not warn that the key grants access to potentially sensitive organization incident data and should be protected from logs, shell history, screenshots, or accidental sharing. In a skill designed for agent use, missing credential-handling guidance increases the risk of inadvertent exposure or misuse of a privileged token.
