Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to store a `WHOP_API_KEY` and automate product creation, license delivery, and affiliate payouts, but it does not warn about the sensitivity of the credential or the risks of triggering real external actions. This can lead users to expose API keys, run unintended financial or account-modifying operations, or deploy the skill without understanding the consequences.
