Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill defines the authentication token as a query parameter and automatically injects it into the request URL. Query-string secrets are commonly exposed via logs, browser/history equivalents, proxy caches, monitoring systems, error messages, and upstream server access logs, making accidental credential disclosure significantly more likely than if the token were sent in an Authorization header.
