Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs users to start a local gateway and references a token, but it does not warn users to keep the token secret, limit binding to localhost, or avoid exposing the service to other hosts. In a deployment skill, omission of these safeguards can lead to accidental credential leakage or unauthorized access to the agent gateway.
