Missing User Warnings
Medium
- Confidence
- 82% confidence
- Finding
- The skill instructs users to set an API key directly in the CLI without any warning about secret handling, shell history exposure, or avoiding key disclosure in shared terminals and logs. In a credential-bearing workflow, omission of basic secret-safety guidance can lead to accidental leakage of a live API key and downstream account abuse.
