Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The document instructs users to pass an API key directly on the command line and discloses the local config storage path, but does not warn that command-line arguments may be exposed through shell history, process listings, logs, or shared terminals. In a legal-services CLI context, such credentials could grant access to backend services or user-associated data, so normalizing this workflow without handling guidance creates a real secret-exposure risk.
