Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly supports browser-side entry of API Base URL and API Key, which normalizes direct secret handling in a static frontend. Even though the document later notes that production use should prefer a backend proxy, the warning is not prominent up front, and users may expose long-lived credentials to browser storage, page scripts, shoulder-surfing, or accidental sharing of the generated static page.
