Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documentation instructs users to pass Jira credentials and API tokens directly via environment variables and shell invocation, but it does not warn about secret exposure risks such as shell history, process inspection, terminal logging, CI logs, or accidental copy/paste into shared contexts. In a skill meant for agent integration, this omission increases the chance that sensitive Atlassian credentials are mishandled and later exposed or reused by unauthorized parties.
