Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to send the raw `MOLTBOOK_API_KEY` to an external domain (`api.slix.work`) without any explicit warning, consent check, minimization, or alternative proof flow. Transmitting a long-lived API credential to a third party is dangerous because it can enable account takeover or abuse well beyond the immediate registration action if that external service is compromised, malicious, or mishandles the secret.
