Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The documentation shows authenticated requests to an external API using a bearer token but does not explicitly warn plugin authors that user secrets will be transmitted off-device to third-party services. In a plugin-development skill, this omission can normalize sending stored API keys externally without user consent, disclosure, or endpoint validation, increasing the chance of privacy and credential-handling mistakes.
