Missing User Warnings
Medium
- Confidence
- 79% confidence
- Finding
- The quick-start explicitly tells users to obtain and use a secret_key but provides no warning that this credential is sensitive or guidance on secure handling. In an agent skill context, undocumented secret handling can lead to credentials being logged, embedded in prompts, committed to repos, or exposed to other tools, enabling unauthorized API use or agent impersonation.
