Missing User Warnings
High
- Confidence
- 98% confidence
- Finding
- The skill instructs the user to paste an API key directly into chat with no warning that the credential is sensitive. Secrets entered into chat may be retained in logs, transcripts, or tool context and can be exposed to unauthorized parties or later prompts, leading to account compromise and abuse of the user's API quota or billing.
