Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 93% confidence
- Finding
The guide tells users to place a live API key in shell environment variables but provides no warning about credential sensitivity, shell history exposure, process inspection, shared terminal sessions, or secure cleanup. In a skill that grants access to Gmail via a gateway, mishandled credentials could let an attacker invoke mailbox-reading or mailbox-modifying operations through the connected account.
- Content
