Missing User Warnings
Low
- Confidence
- 82% confidence
- Finding
- The skill instructs use of an API key via command-line flag or environment variable but provides no warning about secret exposure risks. Passing secrets on the command line can leak them through shell history, process listings, logs, or transcripts, which is a real but relatively limited credential-handling weakness in this context.
