Missing User Warnings
Medium
- Confidence
- 99% confidence
- Finding
- The skill repeatedly embeds hard-coded `admin` credentials (`password="123456"`) in sample connection code without any warning that they are placeholders or unsafe defaults. This normalizes insecure practices and can lead users to deploy privileged accounts with trivial passwords, enabling unauthorized database access and full compromise of DolphinDB instances.
