Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to obtain, store, and reuse a bearer token, but provides only a minimal note to store it securely and no guidance on secret handling, rotation, scoping, or avoiding logs and hardcoded values. In an agent setting, this increases the chance the token is exposed in transcripts, configs, code, or telemetry, enabling unauthorized actions against the user's account.
