Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs storing access and refresh tokens in a local file under the user's home directory, but does not require clear user consent, explain persistence risks, or prefer a secure secret store. Persisted bearer and refresh tokens can be stolen by other local processes, backups, or accidental disclosure, enabling unauthorized account access and API use until revoked or rotated.
