Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs users to store API keys, usernames, and passwords in a plaintext credentials file under the home directory, without any warning about file permissions, encryption, or safer secret-management options. This increases the chance that secrets are exposed to other local users, backups, logs, or malware, leading to account takeover on the referenced external services.
