Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation instructs users to set a live API credential in an environment variable but does not include any warning about keeping the key secret, avoiding hardcoding, or preventing accidental exposure in shell history, screenshots, logs, or committed files. In a skill package that depends on a third-party TTS service, this omission increases the chance of credential leakage and subsequent unauthorized API use or billing abuse.
