Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill sends the authentication token as a query-string parameter, which is then embedded in the full request URL. Query parameters are commonly exposed through logs, browser/history tooling, proxy and CDN logs, monitoring systems, crash reports, and referer-style propagation, making accidental token disclosure more likely even when HTTPS is used.
