Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill requires the authentication token as a query parameter and automatically injects it into the request URL. Query-string secrets are commonly exposed through logs, browser/history artifacts, proxy/CDN telemetry, monitoring systems, and error reports, so the token may be disclosed beyond the intended recipient even though HTTPS is used.
