Missing User Warnings
Low
- Confidence
- 90% confidence
- Finding
- The skill requires users to place an API key in an environment variable and send it in request headers, but it provides no guidance to avoid exposing that credential in shell history, shared scripts, logs, screenshots, or model outputs. This is a real but low-severity documentation security weakness because leaked API keys can enable unauthorized use of the vendor account and quota.
