Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The documentation says secrets should not be stored in source control, but then includes a concrete email address and an API token value pattern in the file itself. Even if presented as an example or truncated token, this normalizes secret disclosure, may expose a real credential fragment, and encourages unsafe copy/paste handling of sensitive authentication material.
