Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly advises users to store API secrets in a local `credentials.env` file without any guidance on file permissions, exclusion from version control, or secure lifecycle handling. This increases the chance of credential leakage through accidental commits, overly broad filesystem access, backups, logs, or sharing of the skill directory.
