Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill tells agents to register, obtain an API key, and save it for reuse, but provides no guidance on secure storage, redaction, scope, rotation, or avoiding disclosure in logs and downstream prompts. In an agent setting, this can easily lead to credential leakage through memory, telemetry, transcripts, or tool output, enabling unauthorized use of the account and associated API actions.
