Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs users to copy Browserbase API credentials into a local .env file without any guidance on secure secret handling, exclusion from version control, or least-privilege usage. This creates a realistic risk of accidental credential disclosure through commits, logs, backups, or shared workspaces, especially in a deployment-oriented skill where users are likely to follow commands verbatim.
