Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly recommends passing the API key in the URL query string, which is commonly logged by browsers, proxies, analytics systems, server access logs, and agent tooling. This can expose the AgentFuel credential to unintended parties, enabling unauthorized use of the account and consumption or transfer of credits.
