Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill instructs users to store a long-lived Google service account JSON key inside the workspace and use it directly for API access, but it does not include any warning about the sensitivity of that key or expectations for secure storage, access controls, rotation, and exclusion from source control. Because service account keys are highly sensitive bearer-equivalent credentials, accidental exposure through the workspace, logs, backups, or repository commits could allow unauthorized access to Google Cloud and Google Analytics resources.
