Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill requires an authentication token to be sent as a query parameter and automatically injects it into the request URL. Query-string credentials are commonly exposed through logs, browser/history tooling, proxies, monitoring systems, crash reports, and upstream infrastructure, making accidental token disclosure more likely than with an Authorization header.
