Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs persisting a write-capable API token in the current working directory, where it may be unintentionally committed, exposed to other tools, or left behind after use. Although file permissions are mentioned, there is no warning about credential sensitivity, safer secret storage options, or lifecycle controls, so the guidance increases the risk of token leakage and misuse.
