Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill defines the authentication token as a query parameter and injects it into the request URL, which can expose the secret in logs, browser/history-equivalents, proxies, monitoring systems, crash reports, and upstream server access logs. Although the request is sent over HTTPS, placing credentials in the URL materially increases the chance of accidental disclosure compared with using an Authorization header.
