Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The usage example reads a GitHub token directly from a local file and injects it into the command line without any warning about credential sensitivity, storage hygiene, or exposure risks. This can normalize insecure secret-handling practices, such as leaving long-lived tokens in plaintext files or exposing them via shell history, process inspection, screenshots, or copied commands.
