Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs an HTTP POST login to a device administration interface using the root account and an unauthenticated/empty password flow, but provides no warning about handling privileged credentials or the risks of sending them over plain HTTP. This exposes highly sensitive management access to interception on the local network and normalizes unsafe admin access patterns for infrastructure devices.
