Missing User Warnings
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to ask the user to paste an access token into the chat, which creates a sensitive-data collection channel in natural language. Chat systems may log, retain, summarize, or expose conversation contents to other components, so collecting bearer tokens there materially increases credential theft and account-compromise risk.
