Missing User Warnings
High
- Confidence
- 99% confidence
- Finding
- The skill instructs users to send an API token in the X-API-Key header to an HTTP endpoint, not HTTPS. That exposes the credential and queried data to interception or modification by any network intermediary, especially on shared, enterprise, or public networks. The skill context makes this more dangerous because the token is required for all queries, so normal use repeatedly transmits the secret in cleartext.
