Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 93% confidence
- Finding
The skill instructs users to place a bearer token into request headers but does not warn that these tokens grant account access and can be exposed through logs, shell history, screenshots, shared notebooks, or agent telemetry. In an agent-skill context, this is more dangerous because automated systems may persist prompts and command examples, increasing the chance of credential leakage to unintended parties.
- Content
