Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs users to place a Bing Webmaster API key in an environment variable or pass it directly on the command line, but it does not warn that this credential is sensitive or note safer handling practices. Command-line arguments can be exposed via shell history and process listings, and local storage guidance without permission or file-mode cautions can lead to inadvertent credential disclosure.
