Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The reference explicitly instructs storing deviceGroupKey, deviceKey, and devicePassword for later logins, but provides no guidance that these are sensitive authentication secrets requiring secure storage. In a skill context, such omission can lead implementers to persist long-lived credentials insecurely in logs, plain files, or agent memory, increasing the risk of account compromise and unauthorized control of home devices.
