Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs users to obtain, store, and reuse a bearer token, but provides no guidance on secret handling, scope minimization, redaction, or avoiding accidental disclosure in logs and transcripts. In an agent setting, this increases the risk that the token is stored insecurely, echoed back to users, or sent to other tools, enabling account takeover of the pet-management account.
