Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The FAQ tells users to print credential-bearing environment variables directly to the terminal, including AK and SK, without any warning that these values are secrets. This can expose credentials through screen sharing, terminal history, logging, or support screenshots, which is especially risky in an IoT/cloud integration where the keys may grant API access to device data or control functions.
