Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The script accepts a bearer token as a positional command-line argument, which can expose the credential through shell history, process listings, audit logs, and orchestration tooling. In this skill's context, the token grants access to a real Avito account API, so leakage could allow unauthorized access to account balance and potentially other account-scoped operations if the token is reused more broadly.
