Missing User Warnings
Medium
- Confidence
- 77% confidence
- Finding
- The documentation shows secrets being exported in shell environment variables and passed directly in a curl header without warning about shell history, terminal logging, CI logs, or screenshot/copy-paste exposure. In an agent-skill context, users may follow examples verbatim, increasing the chance that real project keys are exposed or mishandled.
