Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill documentation instructs users to set an API key directly via CLI commands but provides no warning about secret handling, shell history exposure, or avoiding hardcoding keys in shared terminals/scripts. In a skill specifically designed to interact with a paid external service, this increases the chance of credential leakage and subsequent unauthorized API usage or billing abuse.
