Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to inspect and then source a local credential-bearing config file (`source ~/.atxp/config`) into the current shell without any warning about secret exposure or shell-side effects. In an agent/skill context, this is risky because it normalizes loading sensitive environment data directly from disk and may expose credentials to logs, subprocesses, or later commands executed in the same session.
