Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill tells users to save a bearer token that is shown once but does not explicitly warn that it is a secret or describe secure storage and non-sharing requirements. In practice, users may paste the token into chats, logs, or code repositories, enabling account takeover and unauthorized API actions against their pet account.
