Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to request and pass an API key to commands, but it provides no explicit user-facing warning about credential sensitivity, storage, logging, or exposure in process arguments. Because the agent is expected to run shell commands autonomously, the secret may be exposed via command history, process listings, tool logs, or persisted configuration without informed consent.
