Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells the agent to read a persistent auth token from ~/.rustunnel/config.yml and reuse it in subsequent tool calls. That creates a sensitive-secret handling risk because the agent is encouraged to access stored credentials and pass them around without requiring fresh consent, minimizing exposure, or warning the user that the token is sensitive.
