Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The code appends the API token as a URL query parameter, which can leak secrets through logs, browser history, intermediary proxies, monitoring systems, and error traces even when HTTPS is used. In this skill context, every operation requires the token and the wrapper automatically injects it, so the exposure pattern is systemic rather than isolated.
