Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The setup command embeds the API key directly in a shell command and URL query string, which increases the risk of secret leakage through shell history, process listings, logs, screenshots, clipboard sharing, or terminal recordings. In a skill that explicitly instructs users to configure remote MCP connectivity, this context makes the exposure more dangerous because users are likely to copy-paste the example verbatim during setup.
