Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The setup flow explicitly recommends that users send their API key through chat so the agent can write it to a local config file, but it does not clearly warn that secrets exposed in chat may be visible to the agent, platform, logs, or other retention systems. This increases the chance of credential disclosure through normal use rather than through a technical exploit.
