Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to place account credentials in environment variables and to persist them in ~/.env.local, which can expose secrets through shell history, process environments, backups, logs, or accidental file disclosure. Because this skill handles a real shopping account, compromise could allow unauthorized access to account data and cart/list manipulation, even if it does not support checkout.
