Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document provides concrete instructions for using a bearer API key on every request, including example commands that may encourage operators to paste long-lived credentials into CLI history or code without any warning about storage, rotation, least privilege, or log exposure. In a skill meant to connect autonomous agents to a publishing platform, this increases the chance of credential leakage and subsequent unauthorized use of MCP tools.
