Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill defines the authentication token as a query parameter and appends it into the request URL, which causes the secret to appear in URLs. Query-string tokens are commonly exposed through logs, browser/history storage, proxy infrastructure, monitoring tools, and error messages, making accidental credential disclosure more likely even when HTTPS is used. In this skill's context, the token grants access to a third-party API, so leakage could allow unauthorized API use and access to creator metrics tied to the account.
