Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README tells users to export a live production API key in a shell command example but provides no warning about credential sensitivity, least-privilege usage, or the risk of exposing environment variables in shell history, logs, screenshots, or shared terminals. In an AI-agent context this is more dangerous because users may install and run the tool in automated environments where secrets can be propagated broadly or mishandled by other tools.
