Missing User Warnings
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to persist a user-provided Blotato API key into TOOLS.md, which creates unnecessary credential retention and expands exposure beyond the immediate task. Storing secrets in a local knowledge file can leak them to future prompts, logs, backups, or other skills, enabling unauthorized posting to all connected social accounts.
