Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation advertises commands that store credentials and print a short-lived staff JWT, but provides no warning about secure storage, terminal/log exposure, shell history, or least-privilege handling. In a skill that exposes full Ghost Admin API access, this omission can lead users or downstream agents to reveal or mishandle sensitive tokens, enabling unauthorized administrative actions if those credentials are captured.
