Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation shows privileged credential retrieval using `sudo cat /path/to/root.password`, then posts those credentials to a login endpoint and stores session cookies in `/tmp` without any warning about secret handling, shell history exposure, file permissions, or cleanup. In an agent skill context, examples like this can be copied verbatim into real environments, increasing the chance of credential disclosure or session theft on shared systems.
