Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide instructs users to place a live API key directly into a local JSON config file and provides no warning about credential sensitivity, file permissions, accidental backup/sync exposure, or avoidance of committing secrets to source control. While this is common operational documentation, it normalizes insecure secret handling and can lead to credential disclosure if the config file is readable by other users, synced to cloud storage, or copied into logs/support bundles.
