Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to obtain a user auth code, exchange it for a JWT, and then store and reuse that JWT without any warning about credential sensitivity, storage protections, scope minimization, or user consent for reuse. Because this token is then used against external endpoints to provision proxy access, compromise or over-retention of the JWT could enable unauthorized network use and privacy exposure.
