Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to accept a user-pasted API key, test it, and then remember and reuse it for subsequent requests in the session. Persisting sensitive credentials in conversational state without warning, minimization, or explicit consent increases the risk of unintended disclosure through logs, prompt leakage, debugging output, or cross-turn misuse.
