Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The registration example shows that the service returns an API key directly in the response, and although the document briefly says to save it, it does not clearly warn readers not to share, commit, or log the credential. In a skill intended for autonomous agents, omission of secret-handling guidance increases the chance that API keys end up in logs, transcripts, or source control, enabling account takeover or unauthorized API use.
