Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill explicitly encourages reading JWTs from files, stdin, and curl pipelines without warning that JWTs often contain sensitive authentication and identity data. Users may paste live access tokens into shells, logs, history, or shared environments, leading to inadvertent credential disclosure or misuse.
