Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to create and use a bearer token that is shown once, but it does not warn about storing it securely or avoiding exposure through shell history, terminal logs, screenshots, or pasted commands. Because the token grants authenticated access to the pet account APIs, accidental disclosure could let another party act on the user's account.
