Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly asks the user to provide SSH usernames and passwords, then transmits those secrets to platform APIs, but it does not clearly warn users about sensitive secret handling, storage, logging, or scope of use. In an agent setting, this increases the risk of credential leakage through chat history, logs, telemetry, or unintended downstream processing.
