Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill includes concrete API key setup commands and reveals the default on-disk config location, but does not warn users that the key is a sensitive secret requiring careful handling. In an agent-tooling context, this increases the chance of credential leakage through shell history, pasted commands, logs, shared workspaces, or inadvertent file exposure.
