Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly requires an access token and sends it to an external API endpoint, but the manifest provides no user-facing disclosure about credential handling, third-party transmission, retention, or sharing. This creates a real risk of users supplying sensitive credentials without understanding they are being transmitted to JustOneAPI, which can lead to credential misuse, unauthorized API consumption, or privacy/compliance issues.
