Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill requires the API authentication token to be sent as a URL query parameter, and the code injects it directly into the request URL. Query-string secrets are commonly exposed in logs, browser/history equivalents, monitoring tools, reverse proxies, and upstream services, making accidental credential disclosure significantly more likely even when HTTPS is used.
