Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill defines the API access token as a query parameter and later appends all query parameters directly into the URL. Query-string credentials are commonly exposed through logs, browser history, proxies, monitoring systems, and error telemetry, which increases the chance of credential leakage even when HTTPS is used.
