Missing User Warnings
Low
- Confidence
- 89% confidence
- Finding
- The reference shows passing the API key directly on the command line (`--api-key YOUR_API_KEY`) and exporting it in shell examples without any warning that command-line arguments may be captured in shell history, process listings, logs, or CI output. In a skill intended for agent/operator use, this increases the chance of inadvertent credential exposure even though the document does not appear malicious.
