Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill documentation instructs users to send a bearer token to an external third-party service and does not provide any warning about credential handling, trust boundaries, data retention, or the fact that the token grants authenticated access. In an agent-skill context, normalizing authenticated curl examples without explicit caution can lead users or agents to disclose secrets to an unvetted remote service and increases the chance of credential misuse or unintended account actions.
