Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill defines the API access token as a query parameter and injects it into the request URL. Query-string credentials are commonly exposed in logs, browser/history tooling, proxy caches, observability systems, and error reports, making accidental credential disclosure more likely even when HTTPS is used.
