Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The documentation instructs users to set an API token directly via a CLI command but does not warn that the token is a sensitive credential that may be persisted in shell history, process lists, screenshots, or local CLI config storage. In a skill centered on financial data access, exposed tokens could allow unauthorized API use, quota exhaustion, or access under the user's account.
