Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The API requires a sensitive authentication token in the query string, which is routinely exposed in logs, browser history, analytics systems, reverse proxies, and referrer headers. In an agent/tooling context, this is more dangerous because orchestration layers often record full URLs, making accidental credential disclosure more likely even when transport is encrypted.
