Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 94% confidence
- Finding
The skill explicitly instructs agents to obtain a user JWT, send it in Authorization headers, and states that the JWT can be stored and reused, but it provides no warning about secure storage, minimization, redaction, or scope handling for bearer tokens. In an agent context, reusable bearer tokens are highly sensitive secrets; weak handling can lead to account takeover or unauthorized proxy use if logs, memory, prompts, or downstream tools expose them.
- Content
