Missing User Warnings
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to accept API keys pasted directly into chat and use them for outbound requests, but provides no safeguards for secret handling, redaction, retention, or user warning. This creates a real credential-exposure risk because users may disclose long-lived secrets in conversation transcripts, logs, or downstream tooling, and the skill normalizes unsafe secret-sharing behavior.
