Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to obtain and send a bearer token to a third-party service but provides no warning about safeguarding the token, account takeover risk, or the privacy implications of transmitting sensitive dating/profile/chat data. In an agent skill context, this omission is meaningful because users may paste long-lived credentials into automation flows that could log, reuse, or leak them.
