Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly demonstrates passing a password as a command-line argument, which can expose the secret through shell history, process listings, audit logs, or agent telemetry. Although this is documentation rather than executable code, skills are often followed verbatim by users or agents, so the example normalizes an unsafe credential-handling pattern in a sensitive authentication workflow.
