Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill requires a sensitive API token and places it in the URL query string, which is routinely exposed to logs, proxies, browser/history tooling, monitoring systems, and upstream infrastructure. Even though the request uses HTTPS, query parameters are still more broadly recorded than headers, so the token can be unintentionally disclosed to operators or third-party services.
