Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to configure a Discord webhook URL directly, but does not warn that the URL is effectively a bearer secret that grants message-posting capability to the target channel. Exposing it in shell history, logs, screenshots, or shared configs can let unauthorized parties spam channels, impersonate notifications, or abuse the integration.
