Missing User Warnings
Medium
- Confidence
- 99% confidence
- Finding
- The script sends requests to external APIs over plaintext HTTP, including the API key in the query string. This allows network attackers or intermediaries to intercept or modify responses and steal the credential, which is especially risky because the skill is specifically designed to make frequent outbound requests to a third-party service.
