Missing User Warnings
Medium
- Confidence
- 99% confidence
- Finding
- The script hardcodes the API endpoint as plain HTTP and includes the API key in the query string, so the credential and request data are exposed to interception or modification by any network observer or intermediary. In the context of an agent skill, this is more dangerous because users may supply a reusable API credential and expect the integration to handle it safely, but the skill silently transmits it insecurely.
