Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to save a bearer token and use it in subsequent requests, but it does not warn that the token is a secret or advise secure handling. In an agent setting, this increases the chance that users expose the token in logs, prompts, screenshots, or to other tools, enabling account takeover or unauthorized pet/account actions.
