Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill instructs users to store a long-lived API token in a persistent environment variable and provides setup steps, but it does not warn about credential sensitivity, scope, rotation, or risks of exposing the token through logs, shell history, screenshots, or shared machines. While common, this increases the chance of accidental credential leakage and unauthorized API use if the host environment is compromised or misconfigured.
