Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly recommends passing the API key on the command line with `--api-key sk-ym-xxx` but does not warn that command-line arguments may be exposed via shell history, terminal logs, audit systems, or process listings on multi-user systems. Because this skill is specifically for authenticated API use, users are likely to copy the example verbatim, increasing the chance of credential disclosure and subsequent unauthorized access to the YouMind account and data.
