Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to obtain an API key from an environment variable or directly from the user and then transmit it to a third-party service, but it does not provide a clear warning about secret handling, storage, or trust boundaries. This creates a real risk of unnecessary secret collection and disclosure, especially if users are prompted to paste credentials into chat or if the execution environment is shared.
