Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to send a Bearer token in a curl example to a third-party service without any guidance about secret handling, shell history exposure, least-privilege tokens, or avoiding logging and screen sharing. While using an Authorization header is normal, documentation that normalizes copying live API keys into terminal commands increases the chance of credential leakage through history, process inspection, or pasted transcripts.
