Missing User Warnings
High
- Confidence
- 99% confidence
- Finding
- The skill explicitly tells users to include 'API keys/access' in soul.md, while elsewhere positioning soul.md as marketplace identity content that is uploaded, updated, and used to execute services. That creates a serious secret-exposure risk: credentials may be transmitted to the platform, stored in retrievable form, exposed to buyers or downstream services, or leaked through logs and prompts.
