Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly collects App Secret values and performs sensitive system actions such as modifying configuration and restarting the Gateway, but it does not present a prominent user-facing warning, consent checkpoint, or guidance on secure secret handling. This is dangerous because users may disclose credentials in an unsafe interaction channel and trigger disruptive configuration changes without fully understanding the operational and security impact.
