Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation shows plaintext secret values embedded directly in the config example, including API-key-like tokens, without an adjacent warning that this pattern is unsafe for real deployments. In a configuration reference, users often copy examples verbatim, so this can normalize storing long-lived secrets in files that may be committed, backed up, or exposed through local compromise.
