Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly tells users to save a bearer token and notes it is shown once, but provides no warning about treating it as a secret. This increases the chance users will paste the token into chats, logs, shell history, screenshots, or repos, enabling account takeover or unauthorized API use if exposed.
