Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to collect an AppSecret and persist it via CLI configuration, but it provides no warning to the user about where the secret will be stored, how long it will persist, or who/what processes may later access it. In an agent setting, this increases the risk of credential exposure through shell history, logs, transcripts, config files, or overbroad host access, especially because the secret is handled as plain text.
