Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to supply an API token via environment variable or command-line parameter without any warning that the credential is sensitive, should not be logged, and should not be exposed in process arguments. CLI parameters are especially risky because they may be visible in shell history, process listings, CI logs, or debugging output, increasing the chance of credential disclosure.
