Missing User Warnings
Medium
- Confidence
- 99% confidence
- Finding
- The skill sends the API access token as a URL query parameter, which is commonly logged by clients, proxies, gateways, browser history, and server access logs. Even over HTTPS, placing secrets in the URL increases the chance of accidental credential disclosure and reuse by unauthorized parties.
