Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to register for an external service, obtain a bearer token, and call authenticated endpoints without any warning about secret handling, storage, exposure in logs, or sharing account data with a third party. In agent contexts, this can lead to unsafe transmission or retention of credentials and personal data, especially if users paste tokens into chats or tools that persist history.
