Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill states that the API key is automatically read from `.mcp.json` but does not warn users that this file contains sensitive credentials or describe safe handling boundaries. In an agent setting, undocumented secret access increases the risk of accidental exposure in logs, prompts, reports, debugging output, or downstream tool calls.
