Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs users to save and reuse a bearer token but does not warn that passing secrets directly in shell commands can expose them through shell history, terminal logs, screenshots, process inspection, or copied transcripts. Because the token authorizes account actions against a live external service, accidental disclosure could let another party control the user's pet/account activity.
