External Transmission
Medium
- Category
- Data Exfiltration
- Content
1. Never paste the `trek_` key into files, prompts, logs, screenshots, commits, or shell history intended for sharing. 2. Prefer the agent's native Streamable HTTP MCP support. Configure: - URL: `https://api.superd.fun/mcp` - Header: `Authorization: Bearer <user-key>` 3. Use the Trek CLI to install/sync this Skill, verify the connection, and diagnose failures:
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to transmit a high-privilege `trek_` bearer token to a third-party remote MCP endpoint and also to install and use a remote CLI package. In context, this is the intended integration path, but it still creates a real security risk: a compromised endpoint, package source, or misconfigured agent could expose credentials and grant broad access to the user's Trek data.
