Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The script accepts an API key as a positional command-line argument and passes it directly to the CLI. Command-line arguments are commonly exposed through shell history, process listings, audit logs, and CI job output, so this can leak long-lived credentials to other local users or logging systems.
