Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to place an API token directly into environment variables and later into a local config file, but it provides no warning about secret handling, shell history leakage, file permissions, or avoiding hardcoded credentials. In a skill intended for agent-driven execution, this increases the chance that long-lived credentials are exposed through logs, transcripts, process listings, or overly permissive local files.
