Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill requires the API token to be sent as a URL query parameter, which is unsafe because query strings are commonly logged by clients, proxies, gateways, browser/history systems, and observability tooling. Even though the request uses HTTPS, placing credentials in the URL increases the chance of accidental token disclosure far beyond using an Authorization header.
