Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill includes commands that place AccessKeyID and AccessKeySecret directly on the command line and in exported environment variables without warning about shell history, terminal logging, CI logs, or process-list exposure. In a CLI-focused skill handling cloud credentials, this materially increases the risk of credential leakage and subsequent unauthorized access to Alibaba Cloud resources.
