Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to set an API key directly on the command line but does not warn that command-line arguments may be exposed via shell history, process listings, terminal logs, or transcripts. Because the key grants access to personal fitness data, accidental exposure could allow unauthorized access to sensitive account information.
