Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The documentation explicitly tells users to pass the API key as a command-line argument, which can expose the secret through shell history, process listings, terminal logging, CI logs, or audit tooling. Because this skill is specifically about configuring a production API provider, the likelihood of real credential exposure is materially higher than in a toy example.
