Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill requires an authentication token to be sent as a query parameter, which is commonly logged by client tooling, proxies, browser/history mechanisms, and upstream servers. Even though the request uses HTTPS, placing secrets in the URL increases the chance of accidental disclosure and replay if logs or error traces are exposed.
