Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs users to place Azure API keys in client configuration headers and references environment-variable handling, but it does not clearly warn that keys embedded in config files, JSON snippets, agent settings, or logs can be exposed through source control, shell history, screenshots, telemetry, or proxy/request logging. Because this skill is specifically a local proxy for Azure OpenAI traffic, credential handling is security-sensitive and the provided examples may normalize unsafe copy-paste practices.
