Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the user to handle a live bearer token and make an authenticated request, but it does not include an explicit warning that the token is sensitive or that it must not be exposed in logs, shell history, screenshots, or shared terminals. In a crypto/marketplace context, session tokens can enable account access or financial actions, so normalizing direct token use without safeguards increases the chance of credential leakage.
