Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs users to create a plaintext vault password file with a trivial default value (`abc`) and later uses a hardcoded SSH credential (`password`) for access. Even in a local lab, documenting weak default credentials without an explicit warning normalizes insecure handling of secrets and can lead to credential reuse, accidental disclosure in shell history, filesystems, or screenshots.
