Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The documentation explicitly instructs users to pass the API key as a command-line argument, which can expose the secret through shell history, process listings, audit logs, and terminal recording tools. In a finance-related skill, the API key likely grants access to paid or sensitive market-data services, so accidental disclosure can enable unauthorized API use and account abuse.
