Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The setup guide instructs users to download an OAuth client secret and store both that secret and the resulting cached OAuth token locally, but it does not warn that these files are sensitive or recommend access controls. In a skill intended for operational use with YouTube APIs, these files can grant API access and account-linked capabilities if exposed through source control, backups, shared folders, or multi-user systems.
