Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly instructs users to copy and save a returned API key, but it does not clearly state that the key is a bearer secret that grants inbox and update access and must not be exposed in logs, shell history, screenshots, or shared notes. In security-sensitive workflows, normalizing casual handling of credentials increases the risk of account takeover or unauthorized actions if the key is leaked.
