Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- This code fetches raw GitHub Actions job logs and returns extracted lines to the caller without any masking, redaction, or warning that CI logs may contain secrets, tokens, internal URLs, stack traces, or other sensitive operational data. Even though GitHub masks some known secrets, logs frequently still contain sensitive material from misconfigured workflows or application output, so exposing excerpts through this skill expands the disclosure surface.
