Missing User Warnings
High
- Confidence
- 99% confidence
- Finding
- The file explicitly discloses a hardcoded API key, which is a real secret exposure vulnerability. Anyone with access to the skill can reuse the credential to consume paid API resources, impersonate the account, access associated workflow operations, or trigger quota exhaustion and billing abuse; in a media-generation skill that calls third-party services, this context makes credential leakage especially dangerous because the key likely grants direct external API access.
