Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The manifest requires an API access token to be sent as a query parameter to an external service, but it provides no user-facing disclosure about credential handling or transmission. Query parameters are commonly logged by clients, proxies, and servers, which increases the risk of token leakage and unauthorized reuse if exposed.
