Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill requires a user authentication token as a query parameter, but the manifest provides no user-facing warning about how that credential will be transmitted to a third-party service. Query-string tokens are often exposed in logs, analytics, browser history, proxies, and monitoring systems, increasing the chance of credential leakage or reuse.
