Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the user to persist a bearer API key in a plaintext local file without guidance on file permissions, secret storage, rotation, or preventing accidental disclosure. Any local compromise, misconfigured permissions, backups, logs, or follow-on skills reading dotfiles could expose the credential and allow unauthorized submissions or account access.
