Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to provide long-lived Tencent Cloud `SecretId` and `SecretKey` credentials directly in environment variables and MCP headers, but it does not prominently warn against exposing, logging, committing, or reusing these secrets broadly. If mishandled, these credentials could grant unauthorized access to Tencent Cloud resources and monitoring data, and long-lived keys increase blast radius compared with scoped or ephemeral credentials.
