Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill recommends cloning with a personal access token embedded directly in the HTTPS URL (`https://${GH_TOKEN}@github.com/...`). Tokens placed in command lines and remote URLs can be exposed through shell history, process listings, Git configuration, logs, or by being persisted as the repository's origin URL, creating a realistic credential leakage risk.
