Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill defines the authentication token as a query parameter and later appends all query parameters to the URL before issuing the request. Query-string tokens are routinely exposed through logs, browser/history tooling, monitoring systems, proxy caches, and error telemetry, making credential leakage more likely than if the token were sent in an Authorization header.
