Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to register for and store a long-lived API key, but it does not warn that keys are secrets that must not be exposed in chat logs, task submissions, or third-party links. In an agent setting, this increases the chance of credential leakage through normal tool use or prompt echoing, which could let others act as the agent on the platform.
